THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14863 (HIGH 8.8) — FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation

[NVD] CVE-2026-14863 (HIGH 8.8) — FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation

lownvdPublished 2026-08-11

CVE-2026-14863 CVSS: 8.8 HIGH Published: 2026-08-11T21:17:25.867

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quote

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14863