SQL Injection Vulnerability in FileRun by FileRun
CVE-2026-73698
8.6HIGH
Key Information:
Badges
๐พ Exploit Exists
What is CVE-2026-73698?
FileRun, a file management solution, is affected by a vulnerability that enables SQL injection through the description parameter. This flaw allows delegated or simple administrators to execute arbitrary SQL queries, exploiting flaws in the parameterization of the database queries in the getValuesString() method. Attackers can manipulate the df_users_permissions table to gain superuser privileges. Additionally, they may execute arbitrary code by passing unsanitized path values to the require_once function within the logs listing component. Users are advised to upgrade to version 2026.3.0 or later to mitigate this risk.
Affected Version(s)
FileRun 0 < 2026.3.0
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Valentin Lobstein (Chocapikk)
VulnCheck
