What is CVE-2026-14863?
FileRun versions up to and including 2026.2.0 contain an OS command injection vulnerability allowing authenticated attackers to achieve remote code execution by uploading files with malicious filenames that include shell command substitution sequences. The issue stems from the thumbnail generation system improperly handling filenames. Affected organizations should immediately upgrade to the latest patched version.
Azərbaycanca: FileRun proqramında (2026.2.0 və əvvəlki versiyalar) autentifikasiyadan keçmiş istifadəçilərə qabıq əmri əvəzləmə ardıcıllığı olan zərərli fayl adı yükləməklə sistemdə uzaqdan kod icrası (RCE) əldə etməyə imkan verən OS command injection zəifliyi aşkarlanıb. Problem miniatür yaratma sisteminin fayl adlarını təhlükəsiz emal etməməsindən qaynaqlanır. Təsirlənən təşkilatlara dərhal proqramı ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Does exploiting CVE-2026-14863 require the attacker to be authenticated?
Yes, this OS command injection vulnerability can only be exploited by authenticated users.
What is the root cause of CVE-2026-14863?
The vulnerability stems from the thumbnail generation system improperly handling filenames that include shell command substitution sequences.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.