Junglewise Threat Intelligence

CVE-2026-63358: FileGator privilege escalation via unvalidated chmoditems API endpoint

CVE-2026-63358 · Severity: high · CVSS 7.3 · Published 2026-07-21

Executive brief

FileGator, a multi-user file management application, contains a security flaw in how it handles file permission changes. An authorized user with basic permission to modify files can exploit this to gain full administrative (root) control over the underlying system. This could lead to a total compromise of the server, including unauthorized data access and service disruption.

Technical details

A privilege escalation vulnerability exists in FileGator's '/chmoditems' API endpoint. The application accepts arbitrary Unix permission values from the user and passes them directly to PHP's native 'chmod()' function via 'octdec()' without proper validation or sanitization. An authenticated attacker who already possesses 'chmod' permissions within the application can leverage this lack of validation to modify system-level file permissions, ultimately allowing them to escalate their privileges to root on the host operating system. The issue is addressed in version 7.14.2.

Affected products

  • FileGator FileGator versions before 7.14.2

Timeline

  • 2026-05-18: patched: Fix released in version 7.14.2
  • 2026-07-21: advisory: CVE published by NVD/CISA

References