Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73699— FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

Quick assessment

Affected
FileRun FileRun
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FileRun 2026.3.0 之前的版本存在一个 PHP 对象注入漏洞。经过身份验证的攻击者可以利用 方法中传递给 的不正确选项来执行任意代码——具体而言,代码使用了一个按位置排列的数组,而非用于禁用类实例化的所需具名键数组。拥有数据库写入权限的攻击者可以将一个序列化的小工具链(gadget chain)注入到权限表的列中(这些列在每次经过身份验证的页面加载时都会被处理),从而向可通过 Web 访问的路径写入任意文件(例如 PHP 网页 shell)。

CVSS 7.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73699

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()
Source: CVE Program / CVE List V5
Vulnerability Description
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain into the permissions table columns processed on every authenticated page load to write arbitrary files, such as PHP webshells, to web-accessible paths.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FileRun FileRun 0 ~ 2026.3.0 -

II. Public POCs for CVE-2026-73699

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73699

登录查看更多情报信息。

Vendor Advisories for CVE-2026-73699 (1)

Security Blog Posts for CVE-2026-73699 (1)

Vendor Pages for CVE-2026-73699 (1)

Same Patch Batch · FileRun · 2026-09-10 · 4 CVEs total

CVE-2026-73693 8.8 HIGH FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
CVE-2026-73698 7.2 HIGH FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
CVE-2026-73694 7.2 HIGH FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition

IV. Related Vulnerabilities

V. Comments for CVE-2026-73699

No comments yet


Leave a comment