GROWI 7.5.5 fixes CVE-2026-100727 unauthenticated file read
GROWI 7.5.5, released October 5, 2026, patches CVE-2026-100727, an access-control flaw letting unauthenticated visitors read files from non-public pages. Only deployments using the local upload backend are affected; CVSS 4.0 score is 6.9, CVSS 3.0 is 5.3.
- CWE-552 flaw exposes files by location instead of page permissions
- Affects versions before 7.5.5 with uploads set to "Local"
- CVSS 4.0 score 6.9, CVSS 3.0 score 5.3; confidentiality only
- ZoomEye found 401 hosts titled GROWI as of October 5, 2026
Read next
Security