CVE-2026-63358

Source
https://cve.org/CVERecord?id=CVE-2026-63358
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63358.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63358
Published
2026-07-21T20:13:07.624Z
Modified
2026-07-22T05:30:27.714406263Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
FileGator privilege escalation
Details

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63358.json",
    "cna_assigner": "cisa-cg",
    "cwe_ids": [
        "CWE-732"
    ]
}
References

Affected packages

Git / github.com/filegator/filegator

Affected ranges

Type
GIT
Repo
https://github.com/filegator/filegator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.14.2"
        }
    ]
}

Affected versions

Other
untagged-7bc66f807d09dd18e633
v.*
v.7.4.7
v7.*
v7.0.0
v7.0.0-RC1
v7.0.0-RC2
v7.0.0-RC3
v7.0.1
v7.1.0
v7.1.1
v7.1.2
v7.1.3
v7.1.4
v7.1.5
v7.1.6
v7.10.0
v7.10.1
v7.11.0
v7.11.1
v7.12.0
v7.13.0
v7.13.1
v7.13.2
v7.13.3
v7.13.4
v7.13.5
v7.14.0
v7.14.1
v7.2.0
v7.2.1
v7.3.0
v7.3.1
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.4.0
v7.4.1
v7.4.2
v7.4.3
v7.4.4
v7.4.5
v7.4.6
v7.4.7
v7.5.0
v7.5.1
v7.5.2
v7.5.3
v7.6.0
v7.7.0
v7.7.1
v7.7.2
v7.8.0
v7.8.1
v7.8.2
v7.8.3
v7.8.4
v7.8.5
v7.8.6
v7.8.7
v7.9.0
v7.9.1
v7.9.2
v7.9.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63358.json"