Race Condition Vulnerability in vastsa FileCodeBox Affected by Pickup Limit Handler
CVE-2026-82543
Key Information:
- Vendor
Vastsa
- Status
- Vendor
- CVE Published:
- 30 August 2026
Badges
What is CVE-2026-82543?
A race condition vulnerability has been identified in vastsa FileCodeBox, specifically affecting the update_file_usage function within the Pickup Limit Handler component. This flaw allows an attacker to manipulate the system remotely, potentially leading to unauthorized access or alterations of file usage data. The exploitation of this vulnerability is now public, emphasizing the need for immediate action. Users are strongly advised to upgrade to FileCodeBox version 2.5.0, which includes a patch addressing this issue. The patch is identified by commit hash 8d7d856c62d73badd0797eb4daec8d2ff10a403a.
Affected Version(s)
FileCodeBox 2.0
FileCodeBox 2.1
FileCodeBox 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
