resolved
Unauthenticated testing endpoint of notify_push expose internal IP
Bug reported by chinnuy was disclosed at September 5, 2026, 2:45 pm | Information Disclosure
The testing endpoint of the notify_push component exposed internal IP addresses to unauthenticated users.
resolved
Email Enumeration via Password-Protected Share Identity Verification
Bug reported by cybershinu was disclosed at September 5, 2026, 2:38 pm | Information Disclosure
The vulnerability allowed email enumeration through password-protected share identity verification. Requesting a password for an email share resulted in different response messages depending on whether the email address was the intended recipient, enabling confirmation of the share recipient.
resolved
Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app
Bug reported by nishant baswal was disclosed at September 5, 2026, 2:29 pm | Integer Overflow
The timeamount parameter of the files_retention app lacked proper input validation, allowing an administrator to store an unintended long time amount as the retention period. This vulnerability could have potentially led to files never getting deleted.
resolved
Missing Duplicate Check allowing Multiple Retention Rules per System Tag
Bug reported by charankumar was disclosed at September 5, 2026, 2:23 pm | Business Logic Errors
A bug allowed admins to create multiple retention rules for the same tag, causing potential confusion for other admins.
resolved
Activity app does not verify federated file activity received from remote servers
Bug reported by cyebrsunita was disclosed at September 5, 2026, 2:18 pm | Improper Authentication - Generic
The activity app stored activity content received from remote servers without verifying the content first.