PT-2026-23756 · Flare · Flare

Published

2026-03-04

·

Updated

2026-03-07

·

CVE-2026-30231

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flare versions prior to 1.7.2
Description Flare, a Next.js-based file sharing platform, had a flaw where authenticated, non-owner users could access private files if they knew the file URL. This occurred because the raw and direct file routes only blocked unauthenticated users, lacking the stricter checks used by other endpoints.
Recommendations Update to version 1.7.2 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2026-05297
CVE-2026-30231
GHSA-GWQR-XF5C-5569

Affected Products

Flare