CVE-2026-73699
FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()
Description
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.
In plain language
AI Act nowFileRun versions earlier than 2026.3.0 let a malicious insider with database access take over the server, so affected businesses should upgrade urgently.
Authenticated PHP object injection in FileRun Perms::getPerms() can lead to arbitrary code execution when an attacker with database-write capability injects a serialized payload into permission data.
What to do now
- Check the FileRun version installed on your server and confirm whether it is earlier than 2026.3.0.
- Upgrade FileRun to version 2026.3.0.
- Ask your IT provider to review FileRun permission records and web-accessible folders for unexpected files created before the upgrade.
- Restrict database write access to only the accounts that require it.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-73699 and every CVE in our database. Create a free account — no credit card required.
Create Free Account