CVE Tools

CVE-2026-73698

FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action

Published: Sep 10, 2026Updated: Sep 15, 2026 Sources: CVE List NVDCWE-89

Description

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statement without parameterization. Because the underlying PDO connection uses emulated prepared statements enabling stacked queries, attackers can manipulate the df_users_permissions table to escalate a delegated administrator account to superuser privileges, and may additionally achieve code execution via unsanitized path values passed to require_once in the logs listing component.

In plain language

AI Act now

FileRun before 2026.3.0 lets a malicious or compromised administrator take over the system, so small businesses using it should act now.

Executive summary

Authenticated SQL injection in FileRun’s Groups Add action allows high-privilege users to inject stacked database commands through array-formatted description input and potentially escalate to full control.

If affected, business impact
Full FileRun takeoverPermission changesFile access exposurePotential code executionService disruption

What to do now

  1. Check the installed FileRun version and identify all administrator or delegated-administrator accounts.
  2. Upgrade FileRun to version 2026.3.0.
  3. Until upgraded, restrict administrator access to trusted staff and remove unnecessary delegated-administrator accounts.
  4. Review recent group changes, permission changes, and unfamiliar administrator accounts after upgrading.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:HUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Initial Access
View detailed technique mapping

References

and 1 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-73698 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store