CVE-2026-63358
גבוהה 7.3
תיאור (מקור, אנגלית)
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
מדדים
- CVSS 3.1
-
7.3 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L - CVSS 4.0
-
8.4 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/8/2026
- CWE
- CWE-732
קישורים
- https://github.com/filegator/filegator/blob/master/CHANGELOG.md#7142---2026-05…
- https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55…
- https://github.com/filegator/filegator/tree/master
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/202…
- https://www.cve.org/CVERecord?id=CVE-2026-63358