Instant Hijack: Critical 10.0 CVSS File Browser Flaw Grants Automatic Admin Rights
ID: 048ca87f-5a24-5a85-8060-c1b36a6dcbed
STIX ID: report--048ca87f-5a24-5a85-8060-c1b36a6dcbed
Feed Name: securityonline.info
Threat Score
A critical logic vulnerability (CVE-2026-32760) in File Browser’s public signup handler can grant full administrative rights to any newly registered user when default account settings include perm.admin=true, enabling complete file/system control and potential remote code execution; patch to version 2.62.0 and immediate configuration audits or disabling public signup are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
