{"id":"CVE-2026-63358","summary":"FileGator privilege escalation","details":"FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.","modified":"2026-08-12T03:51:18.103600424Z","published":"2026-07-21T20:13:07.624Z","database_specific":{"cwe_ids":["CWE-732"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63358.json","cna_assigner":"cisa-cg"},"references":[{"type":"WEB","url":"https://github.com/filegator/filegator/tree/master"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63358.json"},{"type":"ADVISORY","url":"https://github.com/filegator/filegator/blob/master/CHANGELOG.md#7142---2026-05-18"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63358"},{"type":"ADVISORY","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63358"},{"type":"FIX","url":"https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/filegator/filegator","events":[{"introduced":"0"},{"fixed":"a5a9b1eb9d33c70a96343d1b29a0a410c53ec6ae"},{"fixed":"4a44ed9a43f84505703dce669c68fb55270c3f2c"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:filegator:filegator:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.14.2"}]}}],"versions":["v7.14.2","v7.14.1","v7.14.0","v7.13.5","v7.13.4","v7.13.3","v7.13.2","v7.13.1","v7.13.0","v7.12.0","v7.11.1","v7.11.0","v7.10.1","v7.10.0","v7.9.3","v7.9.2","v7.9.1","v7.9.0","v7.8.7","v7.8.6","v7.8.5","v7.8.4","v7.8.3","v7.8.2","v7.8.1","v7.8.0","v7.7.2","v7.7.1","v7.7.0","untagged-7bc66f807d09dd18e633","v7.6.0","v7.5.3","v7.5.2","v7.5.1","v7.5.0","v7.4.7","v.7.4.7","v7.4.6","v7.4.5","v7.4.4","v7.4.3","v7.4.2","v7.4.1","v7.4.0","v7.3.5","v7.3.4","v7.3.3","v7.3.2","v7.3.1","v7.3.0","v7.2.1","v7.2.0","v7.1.6","v7.1.5","v7.1.4","v7.1.3","v7.1.2","v7.1.1","v7.1.0","v7.0.1","v7.0.0","v7.0.0-RC3","v7.0.0-RC2","v7.0.0-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63358.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}