Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-63358 Details

Description

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:7.3 HIGHVector:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/filegator/filegator/blob/master/CHANGELOG.md#7142---2026-05-18 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentRelease Notes
https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2c Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentPatch
https://github.com/filegator/filegator/tree/master Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentProduct
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentVDB Entry
https://www.cve.org/CVERecord?id=CVE-2026-63358 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentVDB Entry

Weakness Enumeration

CWE-IDCWE NameSource
CWE-732Incorrect Permission Assignment for Critical ResourceCybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Affected Products

ProductVersions
filegator filegator
< 7.14.2

CPE

  • cpe:2.3:a:filegator:filegator:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-63358
NVD Published Date:
Jul 21, 2026
NVD Last Modified:
Aug 5, 2026
Source:
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CVE-2026-63358 Details - Not Deferred