CVE-2023-31726

HIGH

AList 3.15.1 - Incorrect Access Control

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-31726. PoCs published by J6451.

AI-analyzed exploit summary This PoC exploits an incorrect access control vulnerability in AList 3.15.1, allowing attackers to enumerate directories and obtain sensitive information without authentication.

Description

AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

Exploits (1)

nomisec WORKING POC 3 stars
by J6451 · poc
https://github.com/J6451/CVE-2023-31726

This PoC exploits an incorrect access control vulnerability in AList 3.15.1, allowing attackers to enumerate directories and obtain sensitive information without authentication.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: AList 3.15.1
No auth needed
Prerequisites: Target running AList 3.15.1 · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0106
EPSS Percentile 60.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
alistgo/alist 3.15.1
Published May 23, 2023
Tracked Since Feb 18, 2026