CVE-2024-26261
Estado: AnalizadaCrítica (9.8)—
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.68%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-26261",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-26261",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-29T20:31:28.371408Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "twcert@cert.org.tw",
"affectedData": [
{
"vendor": "Hgiga",
"modules": [
"OAKlouds-organization-2.0",
"OAKlouds-organization-3.0"
],
"product": "OAKlouds",
"versions": [
{
"status": "affected",
"version": "earlier",
"lessThan": "188",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Hgiga",
"modules": [
"OAKlouds-webbase-2.0",
"OAKlouds-webbase-3.0"
],
"product": "OAKlouds",
"versions": [
{
"status": "affected",
"version": "earlier",
"lessThan": "1051",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:hgiga:oaklouds-organization:2.0:*:*:*:*:*:*:*"
],
"vendor": "hgiga",
"product": "oaklouds-organization",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "188",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:hgiga:oaklouds-organization:3.0:*:*:*:*:*:*:*"
],
"vendor": "hgiga",
"product": "oaklouds-organization",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "188",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:hgiga:oaklouds-webbase:2.0:*:*:*:*:*:*:*"
],
"vendor": "hgiga",
"product": "oaklouds-webbase",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1051",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:hgiga:oaklouds-webbase:3.0:*:*:*:*:*:*:*"
],
"vendor": "hgiga",
"product": "oaklouds-webbase",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1051",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-02-15T03:15:35.083",
"references": [
{
"url": "https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html",
"tags": [
"Third Party Advisory"
],
"source": "twcert@cert.org.tw"
},
{
"url": "https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "twcert@cert.org.tw",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded."
},
{
"lang": "es",
"value": "La funcionalidad para descargar archivos en ciertos módulos de HGiga OAKlouds contiene una vulnerabilidad de lectura y eliminación arbitraria de archivos. Los atacantes pueden poner la ruta del archivo en parámetros de solicitud específicos, lo que les permite descargar el archivo sin iniciar sesión. Además, el archivo se eliminará después de descargarlo."
}
],
"lastModified": "2026-06-17T07:17:29.470",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hgiga:oaklouds-organization-2.0:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BDDE14F-3BD2-4AF2-AAFF-BF238F360860",
"versionEndExcluding": "188"
},
{
"criteria": "cpe:2.3:a:hgiga:oaklouds-organization-3.0:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20A6F111-728D-45DE-B7EC-1C3BC9542F78",
"versionEndExcluding": "188"
},
{
"criteria": "cpe:2.3:a:hgiga:oaklouds-webbase-2.0:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C52C10C8-08A1-4CDC-8309-C3F874EBEFF6",
"versionEndExcluding": "1051"
},
{
"criteria": "cpe:2.3:a:hgiga:oaklouds-webbase-3.0:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B80523EB-F1BE-4F09-9613-F7CE2F556056",
"versionEndExcluding": "1051"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "twcert@cert.org.tw"
}