天下漏洞,尽知其名
HIGH

CVE-2026-102249 REBUILD 权限缺失漏洞

影响攻击者可未授权远程操作文件编辑器接口,可能导致文件被篡改

AI 研判

REBUILD 4.4.11 及更早版本中存在一处授权缺失漏洞,位于 /commons/file-editor-save 接口。攻击者可通过操纵 url/fileKey 参数绕过授权校验,且该漏洞利用代码已公开。

影响范围

REBUILD

REBUILD 至 4.4.11 版本(含)受影响,更高版本是否修复暂无公开信息。

漏洞详情

该漏洞属于授权缺失(Missing Authorization)类型,成因是 /commons/file-editor-save 接口未对请求者身份和权限进行有效校验。攻击者可远程构造请求并操纵 url/fileKey 参数,从而在未授权情况下调用文件编辑保存功能。

利用条件与风险

攻击者可远程发起利用,无需有效凭证,且公开利用代码已存在,实战风险较高;厂商未对该披露作出回应。

修复建议

官方暂未发布修复方案,建议关注厂商更新;临时措施包括限制该接口的远程访问、增加身份认证与权限校验,或通过网关/WAF 拦截异常请求。

原始情报

A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.