OS Command Injection Vulnerability in FileRun by FileRun
CVE-2026-14863

8.7HIGH

Key Information:

Vendor

Filerun

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-14863?

CVE-2026-14863 is a severe vulnerability identified in FileRun, a file management software that allows users to organize, share, and collaborate on files and documents. This vulnerability specifically pertains to an OS command injection flaw present in versions up to and including 2026.2.0. It enables authenticated attackers to execute arbitrary commands on the underlying operating system by crafting malicious file names that incorporate shell command substitution sequences. When these files are uploaded, the thumbnail generation system processes the filenames without proper sanitization, leading to the potential execution of unauthorized shell commands via utilities such as ffmpeg and ImageMagick. This could have devastating consequences for organizations, including unauthorized access to sensitive data, full control over server resources, or the introduction of malware.

Potential impact of CVE-2026-14863

  1. Remote Code Execution: The primary risk of CVE-2026-14863 is the ability for attackers to achieve remote code execution on the server, which allows them to run arbitrary commands. This capability can be leveraged to manipulate, steal, or delete sensitive data, significantly compromising organizational security.

  2. Data Breaches: With the ability to execute arbitrary commands, attackers could gain unauthorized access to confidential information. This risk of data exfiltration poses a severe threat to organizations, particularly those handling sensitive client information or proprietary business data.

  3. System Compromise: The exploitation of this vulnerability may lead to a full compromise of the affected server, allowing attackers to install malware, create backdoors for future access, and disrupt normal operations, ultimately affecting business continuity and reliability.

Affected Version(s)

FileRun 0 <= 2026.2.0

FileRun 0 <= 2026.2.0

FileRun 2026.2.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
.