logo

CVE-2026-54414: FileRise Path Traversal Enables Arbitrary File Write and Admin Takeover

ID: 4249e143-62ac-5d4f-a44e-bbfa8cf2450e

STIX ID: report--4249e143-62ac-5d4f-a44e-bbfa8cf2450e

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

**FileRise — CVE-2026-54414:** A critical (CVSS 9.8) unauthenticated path traversal in /api/folder/uploadToSharedFolder.php allows arbitrary file writes (e.g., web shells) and potential administrator takeover; upgrade to FileRise 3.16.0 immediately and follow provided detection and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.