External risk intelligence

Dromara Skyeye SSRF and File Overwrite Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-107781

Dromara Skyeye is a platform that includes document management and collaboration features. The vulnerability exists within an interface intended for handling office file uploads and callbacks. Such functionality is typically exposed as part of a web application or collaborative portal, making it likely to be reachable from the internet in common deployment patterns where users access document management services.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Dromara Skyeye, a platform that includes document management and collaboration features. The issue allows unauthenticated attackers to potentially access internal server resources and overwrite user files, which could have significant implications for data integrity and confidentiality. The main concern is confirming relevance and exposure given the nature of the affected functionality.

  • Attackers can access internal files and overwrite user data.
  • This vulnerability impacts document management and collaboration systems.
  • Confirm relevance and exposure for affected systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a crafted request to the vulnerable component, potentially leading to unauthorized access and modification of files. The attacker initiates the attack by targeting the editUploadOfficeFileById function, which is exposed through the application's interface. By manipulating specific parameters within this function, the attacker can trick the server into fetching external or internal resources and overwriting existing files. The results of this action can then be retrieved using another function.

  • No authentication required.
  • Triggered by an upload callback request.
  • Overwrite files and read results.

Live Threat

Current exploitation, exposure, and threat context

A server-side request forgery vulnerability in Dromara Skyeye, when supported by the advisory's conditions, could allow unauthenticated attackers to make the server fetch internal URLs. This could lead to the overwriting of any user's stored file and subsequent reading of its contents.

  • User-stored files could be overwritten.
  • Arbitrary URLs can be fetched by the server.
  • Sensitive user files may be exposed.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability impacts Dromara Skyeye, specifically its OnlyOffice integration for file handling. Owners of application platforms integrating this functionality or infrastructure teams managing the deployed instances must prioritize identifying all instances, assessing their exposure and business criticality, and confirming the accountable parties. Remediation planning should proceed based on the identified risk.

  • Application or platform owners should manage the issue.
  • Verify Skyeye instance reachability and criticality first.
  • Plan remediation based on risk and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dromara Skyeye?

Dromara Skyeye is a software platform designed for enterprise-level management, which includes integrated features for document storage, collaboration, and office file handling. It is often deployed as a web-based service where teams interact with files and cloud-integrated documents.

How does CVE-2026-107781 affect file security?

This vulnerability is classified as Server-Side Request Forgery (CWE-918). It allows an unauthenticated party to manipulate the server into reaching out to arbitrary locations. By abusing the OnlyOffice callback mechanism, an attacker can trick the server into fetching external data and overwriting sensitive user-stored files.

What triggers the vulnerability in Skyeye?

The flaw is triggered when a crafted request is sent to the editUploadOfficeFileById function. An attacker provides malicious URL and key parameters to the application. Requests that do not interact with this specific callback interface or lack the necessary structure to manipulate file paths do not trigger this bug.

Is my Skyeye instance reachable from the internet?

Halo Surface Signal notes that since Skyeye provides collaborative document management, these services are frequently placed on internet-facing web portals to support remote access. If your installation is accessible from the public internet to facilitate document sharing, it is more likely to be reachable by external attackers.

What should I do if I run Dromara Skyeye?

First, identify all active instances of Skyeye within your infrastructure and determine which ones utilize the OnlyOffice file handling features. Evaluate the business criticality of those specific servers, confirm who is responsible for their maintenance, and prioritize those instances for remediation planning.

References