Impact
FileRun before 2026.3.0 contains a SQL injection flaw that allows delegated or simple administrators to inject an array in the description parameter, causing raw array values to be interpolated into an INSERT statement via the getValuesString() method. prepared statements that allow stacked queries, attackers can modify the df_users_permissions table and promote a delegated administrator to a superuser account. Additionally, the logs component unsafely passes user‑supplied path values to require_once, which can enable code execution if an attacker crafts a suitable payload.
Affected Systems
Any FileRun installation running a version older than 2026.3.0 is impacted. The flaw is triggered when the affected user submits the Groups Add action through the web interface, so all deployments with delegated or simple administrator roles that can perform that action are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 8.6, indicating high severity. The attack vector requires authenticated access as a delegated or simple administrator, so the impact is limited to accounts with those privileges, but the consequences include privilege escalation and potential code execution. The EPSS score is not available, so the exact exploitation probability is unknown; however, the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation campaigns yet. immediate remediation.
OpenCVE Enrichment