← Späť na vyhľadávanie CVE

CVE-2026-10031

SFTPGo

Popis

SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link-s directory permissions rather than the dereferenced target-s directory permissions.

CVSS 4.2EPSS 0.181%Riziko 0.43
Zobraziť zdroj
Zverejnené
2026-07-30 23:16:51
Dotknuté verzie
<2.7.4
Typ
Kritický softvér
Posledná úprava
2026-07-31 20:16:46
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N