CVE-2024-26261: Hgiga Oaklouds-Organization-2.0
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
Affected products
- Hgiga Oaklouds-Organization-2.0: before 188 (fixed in 188)
- Hgiga Oaklouds-Organization-3.0: before 188 (fixed in 188)
- Hgiga Oaklouds-Webbase-2.0: before 1051 (fixed in 1051)
- Hgiga Oaklouds-Webbase-3.0: before 1051 (fixed in 1051)
Published 2024-02-15. Last modified 2026-06-17.