CVE-2026-29515
MiCode FileExplorer SwiFTP Server Authentication Bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.
| CWE | CWE-303 |
| Vendor | micode |
| Product | fileexplorer |
| Published | Mar 11, 2026 |
| Last Updated | Mar 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for micode fileexplorer
Be the first to know when new unknown vulnerabilities affecting micode fileexplorer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MiCode / FileExplorer
0
References
Credits
XavLimSG VulnCheck