Executive brief
FileGator, a multi-user file management application, contains a security flaw in how it handles file permission changes. An authorized user with basic permission to modify files can exploit this to gain full administrative (root) control over the underlying system. This could lead to a total compromise of the server, including unauthorized data access and service disruption.
Technical details
A privilege escalation vulnerability exists in FileGator's '/chmoditems' API endpoint. The application accepts arbitrary Unix permission values from the user and passes them directly to PHP's native 'chmod()' function via 'octdec()' without proper validation or sanitization. An authenticated attacker who already possesses 'chmod' permissions within the application can leverage this lack of validation to modify system-level file permissions, ultimately allowing them to escalate their privileges to root on the host operating system. The issue is addressed in version 7.14.2.
Affected products
- FileGator FileGator versions before 7.14.2
Timeline
- 2026-05-18: patched: Fix released in version 7.14.2
- 2026-07-21: advisory: CVE published by NVD/CISA
References
- https://github.com/filegator/filegator/blob/master/CHANGELOG.md
- https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2c
- https://github.com/filegator/filegator/tree/master
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json
- https://www.cve.org/CVERecord?id=CVE-2026-63358