Published:2026/10/05  Last Updated:2026/10/05

JVN#24352487
GROWI vulnerable to improper access control

Overview

GROWI provided by GROWI, Inc. contains an improper access control vulnerability.

Products Affected

  • GROWI versions prior to v7.5.5
Note that the product is affected when the file upload setting is configured as "Local".

Description

GROWI provided by GROWI, Inc. contains the following vulnerability:

  • Files or Directories Accessible to External Parties (CWE-552)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 5.3
    • CVE-2026-100727

Impact

A remote unauthenticated attacker may be able to read files contained in non-public pages of the product.

Solution

Update the Software
Update the software to the latest version. The developer has released the following version to address this vulnerability.

  • GROWI v7.5.5

Vendor Status

Vendor Status Last Update Vendor Notes
GROWI, Inc. Vulnerable 2026/10/05 GROWI, Inc. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

GROWI, Inc. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and GROWI, Inc. coordinated under the Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-100727
JVN iPedia JVNDB-2026-000144