PatchSiren

FileGator CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FileGator CVE published 2026-07-21

CVE-2026-63358

FileGator is vulnerable to privilege escalation due to accepting arbitrary Unix permission values via the '/chmoditems' API endpoint. An authenticated user with 'chmod' permission can upgrade their privileges to root. This vulnerability allows an attacker to gain elevated privileges, potentially leading to unauthorized access and control of the system. The vulnerability is caused by a lack of validation i [truncated]