Description
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
References (5)
Core 5
Core References
Release Notes release-notes
url
https://github.com/filegator/filegator/blob/master/CHANGELOG.md#7142---2026-05-18
Patch patch
url
https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2c
Third Party Advisory third-party-advisory
url
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json
Scores
CVSS v3
7.3
EPSS
0.0011
EPSS Percentile
1.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-732
Status
published
Products (2)
FileGator/FileGator
< 7.14.2
FileGator/FileGator
7.14.2
Published
Jul 21, 2026
Tracked Since
Jul 22, 2026