CVE-2026-24897Disclosure(erugo / erugo)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch erugo erugo systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when creating shares. By specifying a writable path within the public web root, an attacker can upload and execute arbitrary code on the server, resulting in remote code execution (RCE). This vulnerability allows a low-privileged user to fully compromise the affected Erugo instance. Version 0.2.15 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-94CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erugo

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-01-28); latest day: 3
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
erugo

Deep dive

Activity timeline6 mentions / 2d
01223Mentions · 2026-01-28: 3Mentions · 2026-01-29: 3PoC Mentioned / Linked · 2026-01-28: 1Patch / Workaround · 2026-01-29: 2Technical Details · 2026-01-28: 3Technical Details · 2026-01-29: 301-2801-29
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-283
Disclosure3
2026-01-293
Disclosure1Patch2
Full discourse6 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24897: CRITICAL] Erugo file-sharing platform versions up to 0.2.14 have a security flaw allowing RCE. Update to v0.2.15 to address the vulnerability and enhance cyber security.#cve,CVE-2026-24897,#cybersecurity https://cvefind.com/CVE-2026-24897

    Post summary

    The tweet alerts to a critical RCE flaw in Erugo file-sharing platform versions up to 0.2.14 and recommends upgrading to v0.2.15 to mitigate the threat.

    1000099
    584 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An authenticated RCE via arbitrary file upload affects Erugo (CVE-2026-24897). Update to remediate. #RCE #InfoSec #Erugo https://www.pulsepatch.io/posts/cve-2026-24897-erugo-authenticated-rce

    Post summary

    An authenticated remote code execution vulnerability via arbitrary file upload has been disclosed for Erugo (CVE‑2026‑24897), and a remediation update is available.

    0000056
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24897 Authenticated Path Traversal in Erugo File-Sharing Platform Leads to Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24897

    Post summary

    The post announces CVE‑2026‑24897, an authenticated path traversal flaw in the Erugo file‑sharing platform that can lead to remote code execution, but it provides no details about exploits, patches, or active attacks.

    00000114
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-24897 - Critical Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insu... https://www.thehackerwire.com/vulnerability/CVE-2026-24897/ https://t.co/LitC2QTLEJ

    Post summary

    The post discloses that Erugo 0.2.14 allows low‑privileged users to upload arbitrary files, a critical path‑traversal flaw.

    0000068
    113 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24897 Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified… https://www.cve.org/CVERecord?id=CVE-2026-24897

    Post summary

    CVE-2026-24897 identifies an authenticated low‑privileged file upload vulnerability in Erugo up to version 0.2.14, allowing users to upload arbitrary files to specified locations. No PoC, exploit code, or patch information is provided.

    00000248
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-24897: Authenticated Remote Code Execut... Path traversal in Erugo leads to trivial RCE for any authenticated user - upload to web root and game over. Perfect pri... https://zerodaysignal.com/vulnerability/CVE-2026-24897 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a path traversal vulnerability (CVE-2026-24897) in Erugo that allows authenticated users to upload files to the web root, leading to trivial remote code execution; a PoC link is provided.

    0000087
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apperugoerugo---

Explore more