Arbitrary Permission Escalation in FileGator by FileGator Team
CVE-2026-63358

8.4HIGH

Key Information:

Vendor

Filegator

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-63358?

An vulnerability exists in FileGator that enables an authenticated user with 'chmod' permission to modify Unix permissions arbitrarily through the '/chmoditems' API endpoint. This flaw arises from the lack of validation and direct transmission of permission values to PHP's 'chmod()' function via 'octdec()' conversion. Exploiting this allows users to elevate their privileges to root, potentially compromising the integrity and security of the system.

Affected Version(s)

FileGator 0 < 7.14.2

FileGator 7.14.2

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Moiz
.