Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 30, 2026
FileGator privilege escalation
CVE-2026-63358
Description
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2cmitrepatch
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.jsonmitrethird-party-advisory
- github.com/filegator/filegator/blob/master/CHANGELOG.mdmitrerelease-notes
- github.com/filegator/filegator/tree/mastermitreproduct
- www.cve.org/CVERecordmitrevdb-entry
News mentions
0No linked articles in our index yet.