In Pydio Cells, the process for creating external users (for file sharing) does not properly restrict the roles that can be assigned to these users. By manipulating the HTTP request during external user creation, an attacker can assign arbitrary roles, including privileged ones, to the new user. This results in the external user gaining access to all cells and non-personal workspaces, far beyond the intended scope.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, standalone Python proof-of-concept exploit for CVE-2023-32749 affecting Pydio Cells 4.1.2 and earlier. It contains only two files: a README describing the vulnerability and usage, and a single executable script, pydio_privesc.py. The exploit is not part of a larger framework. The script takes four command-line arguments: target base URL, Bearer token, new username, and new password. It disables TLS certificate verification, creates a requests session, and authenticates solely with the supplied Bearer token. First, it sends a POST request to <base_url>/a/user with an empty JSON body to retrieve user data. From the returned Users array, it extracts every role UUID present across users and builds a deduplicated role list. It then sends a PUT request to <base_url>/a/user/<new_user> with JSON specifying the new login, password, profile attribute set to shared, and the full collected role list. If successful, it reports that the new user was created with all roles assigned. Operationally, this is a privilege-escalation/account-creation exploit rather than code execution. Its main capability is converting an existing low-privileged authenticated session into a broadly privileged account by abusing improper authorization in the user-management API. The exploit does not include a shell payload or post-exploitation automation; instead, the outcome is unauthorized access to shared cells and non-personal workspaces through the newly created account.
This repository is a proof-of-concept (PoC) exploit for CVE-2023-32749, targeting Pydio Cells version 4.1.2. The exploit is implemented in Python (exploit.py) and requires the 'requests' library (specified in requirements.txt). The script takes valid user credentials and a target URL, authenticates to the Pydio Cells REST API, enumerates all user roles, and creates a new user ('foobar' with password 'hunter2') assigned to all available roles, effectively achieving privilege escalation. The main attack vector is via the network, exploiting exposed REST API endpoints. The README.md provides usage instructions and references. No hardcoded IPs or domains are present; the target URL is supplied by the user at runtime. The exploit is a functional PoC and not weaponized, as it requires manual input and does not automate post-exploitation actions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.