OS Command Injection Vulnerability in FileRun by FileRun
CVE-2026-14863

8.7HIGH

Key Information:

Vendor

Filerun

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-14863?

FileRun versions up to and including 2026.2.0 are vulnerable to an OS command injection issue. This vulnerability enables authenticated attackers to perform remote code execution by uploading files with specially crafted filenames. The system's thumbnail generation feature incorrectly passes these filenames to the exec() function without proper sanitization, allowing potential command substitution sequences to be executed. This flaw could lead to severe consequences if exploited, as malicious payloads embedded in filenames may execute shell commands during the processing of uploaded files.

Affected Version(s)

FileRun 0 <= 2026.2.0

FileRun 0 <= 2026.2.0

FileRun 2026.2.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
.