VYPR
High severity7.3NVD Advisory· Published Jul 21, 2026· Updated Aug 5, 2026

CVE-2026-63358

CVE-2026-63358

Description

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Filegator/filegatorllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • cpe:2.3:a:filegator:filegator:*:*:*:*:*:*:*:*range: <7.14.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.