SQL Injection Vulnerability in FileRun by FileRun
CVE-2026-73698

8.6HIGH

Key Information:

Vendor

Filerun

Status
Vendor
CVE Published:
10 September 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-73698?

FileRun, a file management solution, is affected by a vulnerability that enables SQL injection through the description parameter. This flaw allows delegated or simple administrators to execute arbitrary SQL queries, exploiting flaws in the parameterization of the database queries in the getValuesString() method. Attackers can manipulate the df_users_permissions table to gain superuser privileges. Additionally, they may execute arbitrary code by passing unsanitized path values to the require_once function within the logs listing component. Users are advised to upgrade to version 2026.3.0 or later to mitigate this risk.

Affected Version(s)

FileRun 0 < 2026.3.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
VulnCheck
.