CVE-2026-82543

Source
https://cve.org/CVERecord?id=CVE-2026-82543
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82543.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82543
Published
2026-08-30T12:45:11.353Z
Modified
2026-09-01T03:46:15.206965729Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
vastsa FileCodeBox Pickup Limit views.py update_file_usage race condition
Details

A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function updatefileusage of the file apps/base/views.py of the component Pickup Limit Handler. Performing a manipulation results in race condition. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 2.5.0 is able to resolve this issue. The patch is named 8d7d856c62d73badd0797eb4daec8d2ff10a403a. Upgrading the affected component is recommended.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82543.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-362"
    ]
}
References

Affected packages

Git / github.com/vastsa/filecodebox

Affected ranges

Type
GIT
Repo
https://github.com/vastsa/filecodebox
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "2.1"
        },
        {
            "last_affected": "2.1"
        },
        {
            "introduced": "2.2"
        },
        {
            "last_affected": "2.2"
        },
        {
            "introduced": "2.3"
        },
        {
            "last_affected": "2.3"
        }
    ]
}

Affected versions

2.*
2.0
2.1
2.2
2.3
V2.*
V2.0
V2.1
V2.3
V2.4
v2.*
v2.2.1
v2.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82543.json"