Skip to content
CVE Alert: CVE-2026-73698 – FileRun

CVE Alert: CVE-2026-73698 – FileRun

Redpacketsecurity admin September 11, 2026

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statement without parameterization. Because the underlying PDO connection uses emulated prepared statements enabling stacked queries, attackers can manipulate the df_users_permissions table to escalate a delegated administrator account to superuser privileges, and may additionally achieve code execution via unsanitized path values passed to require_once in the logs listing component.

High risk for internet-accessible deployments; urgent prioritisation is warranted if KEV inclusion or active SSVC exploitation is confirmed, but those indicators and EPSS are not provided.

A compromised privileged account could expose, alter or destroy stored files and associated metadata. The ability to manipulate authorisation records creates a credible route from administrative misuse to full platform takeover, with potential follow-on code execution and ransomware impact. The primary uncertainty is whether exploitation is currently observed in the wild.

### Most likely attack path

An attacker needs network access and a delegated or simple administrator account, but no victim interaction; low complexity makes reliable exploitation plausible once authenticated. Scope is unchanged in the scoring model, yet elevated application privileges could enable broad tenant impact and provide a stepping stone to connected storage or identity systems.

### Who is most exposed

Organisations publishing the FileRun interface to the internet, particularly those using delegated administration for customers, partners or helpdesk teams, face the greatest exposure. Multi-tenant file-sharing instances and installations integrated with sensitive repositories warrant immediate review.

Review web and application logs for unusual array-form parameters in group-management requests.

Alert on administrative permission changes, especially delegated accounts becoming superusers.

Hunt for unexpected SQL errors, stacked-query patterns or anomalous database writes.

Investigate web-process file reads, includes or child-process creation following suspicious sessions.

### Mitigation and prioritisation

Upgrade to the vendor’s fixed release promptly; treat as priority 1 if KEV is true or EPSS is at least 0.5.

Restrict administrative endpoints by VPN, trusted IP ranges and least privilege.

Rotate administrator credentials and review all delegated roles for unauthorised changes.

Test the update in a representative environment, then expedite change approval for internet-facing systems.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.