THREAT OPS › Threat News › [NVD] CVE-2026-14863 (HIGH 8.8) — FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation
[NVD] CVE-2026-14863 (HIGH 8.8) — FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation
CVE-2026-14863 CVSS: 8.8 HIGH Published: 2026-08-11T21:17:25.867
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quote
Indicators of compromise
- CVE-2026-14863cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14863