CVE-2026-73698
FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
No known exploitation. EPSS puts it in the 48th percentile. No fix published yet.
What to do
No fixed build or workaround is published yet. Limit exposure and watch for a patch.
Steps
Written by AI from the record- Check the installed FileRun version and identify all administrator or delegated-administrator accounts.
- Upgrade FileRun to version 2026.3.0.
- Until upgraded, restrict administrator access to trusted staff and remove unnecessary delegated-administrator accounts.
- Review recent group changes, permission changes, and unfamiliar administrator accounts after upgrading.
What it is
From the CVE record
FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statement without parameterization. Because the underlying PDO connection uses emulated prepared statements enabling stacked queries, attackers can manipulate the df_users_permissions table to escalate a delegated administrator account to superuser privileges, and may additionally achieve code execution via unsanitized path values passed to require_once in the logs listing component.
In plain language
Written by AI from the recordFileRun before 2026.3.0 lets a malicious or compromised administrator take over the system, so small businesses using it should act now.
Authenticated SQL injection in FileRun’s Groups Add action allows high-privilege users to inject stacked database commands through array-formatted description input and potentially escalate to full control.
If you're affected
- Full FileRun takeover
- Permission changes
- File access exposure
- Potential code execution
- Service disruption
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
0.6% chance of exploitation activity in the next 30 days, which ranks it in the 48th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
5 events over 5 days, from the signal feeds we watch.
- Record updated
- Publishedweakness classified, att&ck mapped, record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Scored 7.2 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required HighRequires admin or elevated privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Initial AccessT1190Exploit Public-Facing Applicationhigh confidence
Sources
References in the record
- vulncheck.com/blog/filerun-delegated-admin-sql-to-object-injection-rce
- filerun.com/index.php/changelog?v=2026.3.0
- vulncheck.com/advisories/filerun-authenticated-sql-injection-via-groups-add-action
And 1 more reference. See all after sign-in
In the news
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for FileRun, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI