Skip to content
Critical SQL Injection Vulnerabilities in FileRun Lead to RCE Risks

Critical SQL Injection Vulnerabilities in FileRun Lead to RCE Risks

First seen 11 Sep 2026, 00:45 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 07:17 UTC
  • Four critical vulnerabilities in FileRun allow remote code execution.
  • CVE-2026-73698 enables SQL injection for privilege escalation.
  • FileRun versions before 2026.3.0 are vulnerable; immediate patching is essential.

VulnCheck disclosed four vulnerabilities in FileRun, a self-hosted file management platform, allowing remote code execution (RCE) via SQL injection and deserialization flaws. The vulnerabilities are identified as CVE-2026-73693, CVE-2026-73694, CVE-2026-73698, and CVE-2026-73699, all published on 2026-09-10. The most severe, CVE-2026-73698, enables delegated administrators to execute arbitrary SQL, potentially escalating privileges to superuser. Exploitation can lead to unauthorized access, data manipulation, and code execution. FileRun versions prior to 2026.3.0 are affected, with the latest release addressing these issues. Organizations using FileRun, especially those exposing it to the internet, are at high risk. Immediate upgrades to the patched version are recommended to mitigate the threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-06
FileRun 2026.3.0 released
The new version of FileRun addresses all four vulnerabilities disclosed.
vulncheck.com
2026-09-10
CVE-2026-73693 published
VulnCheck disclosed a vulnerability in FileRun allowing RCE via command injection.
vulncheck.com
2026-09-10
CVE-2026-73694 published
A superuser settings test endpoint vulnerability in FileRun was disclosed.
vulncheck.com
2026-09-10
CVE-2026-73698 published
A SQL injection vulnerability allowing arbitrary SQL execution by delegated admins was disclosed.
redpacketsecurity.com
2026-09-10
CVE-2026-73699 published
A deserialization flaw in FileRun was disclosed, allowing arbitrary class instantiation.
vulncheck.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-73693 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed