Race Condition Vulnerability in vastsa FileCodeBox Affected by Pickup Limit Handler
CVE-2026-82543

6.9MEDIUM

Key Information:

Vendor

Vastsa

Vendor
CVE Published:
30 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-82543?

A race condition vulnerability has been identified in vastsa FileCodeBox, specifically affecting the update_file_usage function within the Pickup Limit Handler component. This flaw allows an attacker to manipulate the system remotely, potentially leading to unauthorized access or alterations of file usage data. The exploitation of this vulnerability is now public, emphasizing the need for immediate action. Users are strongly advised to upgrade to FileCodeBox version 2.5.0, which includes a patch addressing this issue. The patch is identified by commit hash 8d7d856c62d73badd0797eb4daec8d2ff10a403a.

Affected Version(s)

FileCodeBox 2.0

FileCodeBox 2.1

FileCodeBox 2.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Galaxyn (VulDB User)
.