CVE-2026-54414: FileRise Path Traversal Enables Arbitrary File Write and Admin Takeover
ID: 4249e143-62ac-5d4f-a44e-bbfa8cf2450e
STIX ID: report--4249e143-62ac-5d4f-a44e-bbfa8cf2450e
Feed Name: CosmicBytez Labs
Threat Score
**FileRise — CVE-2026-54414:** A critical (CVSS 9.8) unauthenticated path traversal in /api/folder/uploadToSharedFolder.php allows arbitrary file writes (e.g., web shells) and potential administrator takeover; upgrade to FileRise 3.16.0 immediately and follow provided detection and hardening guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
