CVE-2026-73698
FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statement without parameterization. Because the underlying PDO connection uses emulated prepared statements enabling stacked queries, attackers can manipulate the df_users_permissions table to escalate a delegated administrator account to superuser privileges, and may additionally achieve code execution via unsanitized path values passed to require_once in the logs listing component.
| CWE | CWE-89 |
| Vendor | filerun |
| Product | filerun |
| Published | Sep 10, 2026 |
| Last Updated | Sep 15, 2026 |
Get instant alerts for filerun filerun
Be the first to know when new high vulnerabilities affecting filerun filerun are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H