High severity7.3NVD Advisory· Published Jul 21, 2026· Updated Aug 5, 2026
CVE-2026-63358
CVE-2026-63358
Description
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2cnvdPatch
- github.com/filegator/filegator/blob/master/CHANGELOG.mdnvdRelease Notes
- github.com/filegator/filegator/tree/masternvdProduct
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.jsonnvdVDB Entry
- www.cve.org/CVERecordnvdVDB Entry
News mentions
0No linked articles in our index yet.