PatchSiren

drakkan CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW drakkan CVE published 2026-07-30

CVE-2026-10031

CVE-2026-10031 is a permission bypass vulnerability in SFTPGo versions prior to 2.7.4. This vulnerability allows authenticated users with create_symlinks permission to create symbolic links in permitted directories, potentially leading to unauthorized access or modification of files in restricted directories. The vulnerability exists because operations are authorized against the link's directory permissio [truncated]