CVE-2026-29515Disclosure(xiaomi / fileexplorer)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-303CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fileexplorer

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-11)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
fileexplorer

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-03-11: 2Mentions · 2026-05-11: 4Technical Details · 2026-03-11: 2Technical Details · 2026-05-11: 303-1105-11
Signal classification1 categories
Disclosure
6100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure2
2026-05-114
Disclosure4
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/cve-2026-29515-xiaomi-fileexplorer #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet points to a research article announcing CVE‑2026‑29515 for Xiaomi FileExplorer but provides no further details or evidence of exploitation.

    0000014
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-29515 (CVSS 9.8) — xiaomi fileexplorer. CVE: CVE-2026-29515 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces the critical CVE-2026-29515 affecting Xiaomi File Explorer, noting its CVSS score and severity, but provides no exploits, patches, or claims of active use.

    0000033
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-29515 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers…

    Post summary

    The advisory discloses an authentication bypass vulnerability in MiCode FileExplorer’s embedded SwiFTP FTP server component, rated CVSS 9.8 and critical severity, potentially permitting network attackers unrestricted access.

    0000079
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-29515 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This advisory confirms CVE‑2026‑29515 as a critical vulnerability with a CVSS 9.8 score, but it provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000026
    197 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29515 MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid … https://www.cve.org/CVERecord?id=CVE-2026-29515

    Post summary

    CVE-2026-29515 is an authentication bypass vulnerability in MiCode FileExplorer’s embedded SwiFTP FTP server component, enabling network attackers to log in without valid credentials.

    0000096
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-29515: MiCode FileExplorer SwiFTP Serve... SwiFTP's PASS handler grants access to any credentials - network-accessible file server with zero authentication is eve... https://zerodaysignal.com/vulnerability/CVE-2026-29515 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-29515 is disclosed as a vulnerability in SwiFTP allowing unauthorized credential access via the PASS handler, with no defenses or exploitation evidence reported.

    0000033
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxiaomifileexplorer---

Explore more