CVE-2026-100727EPSS p13.1%
CVE-2026-100727CVE-2026-100727
Description
An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when the file upload setting is configured as "Local".
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.23% probability of exploitation · percentile 13.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-05 |