CVE Tools

CVE-2026-73699

FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

Published: Sep 10, 2026Updated: Sep 10, 2026 Sources: CVE List NVDCWE-502

Description

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.

In plain language

AI Act now

FileRun versions earlier than 2026.3.0 let a malicious insider with database access take over the server, so affected businesses should upgrade urgently.

Executive summary

Authenticated PHP object injection in FileRun Perms::getPerms() can lead to arbitrary code execution when an attacker with database-write capability injects a serialized payload into permission data.

If affected, business impact
Full server takeoverUnauthorized file creationMalicious server softwareBusiness service disruptionStored file exposure

What to do now

  1. Check the FileRun version installed on your server and confirm whether it is earlier than 2026.3.0.
  2. Upgrade FileRun to version 2026.3.0.
  3. Ask your IT provider to review FileRun permission records and web-accessible folders for unexpected files created before the upgrade.
  4. Restrict database write access to only the accounts that require it.
Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:HUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Execution
Initial Access
View detailed technique mapping

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-73699 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store