CVE-2026-14863Disclosure

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be evaluated as shell commands when ffmpeg, ImageMagick, vips, or stl-thumb processes the file during thumbnail generation.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-15: 1Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-17: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 108-1508-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Caitlin Condon@catc0n
    Disclosure

    New vulnerability disclosure from @Chocapikk_ : CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K+ based on the team's ASM queries. Good stuff as always 🎉 https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce

    Post summary

    The message announces the discovery of CVE‑2026‑14863, an OS command injection that escalates to remote code execution in FileRun. It provides basic technical details but no PoC, exploit code, or patch information.

    1612952.8K
    3.6K followersView on X
  • VulnCheck@VulnCheckAI
    Disclosure

    VulnCheck disclosed CVE-2026-14863, a command injection vulnerability in FileRun that could allow attackers to achieve RCE through malicious filenames. Read the analysis from @Chocapikk_: https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce

    Post summary

    VulnCheck announced CVE-2026-14863, a command injection flaw in FileRun that can lead to RCE through crafted filenames, with additional analysis available in a linked blog post.

    00000216
    840 followersView on X

Explore more