CVE-2026-3266: Opentext Filr

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

Affected products

  • Opentext Filr: before 25.1.3 (fixed in 25.1.3)

Published 2026-03-03. Last modified 2026-06-17.