CVE-2026-63358·PHP vulnerability
FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their privileges to root.
- Severity
- high
- Software
- PHP
- Fixed in
- 7.14.2
- Published
- 2026-07-21
Affected versions
Until: 7.14.2
Fixed in: 7.14.2
How to fix this CVE
Update FileGator to version 7.14.2 or later to patch a privilege escalation vulnerability in the chmod API endpoint. The vulnerability stems from insufficient validation of Unix permission parameters before they are passed to PHP's chmod() function. Immediately apply this security update to prevent authenticated attackers from escalating their privileges to root.
sudo dnf update phpDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /chmoditems HTTP/1.1.*permission[^0-7]|chmod.*[^0-7]{3,4}|octdec.*[a-zA-Z0-9]{5,}WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or restrict POST requests to /chmoditems API endpoint to only authorized administrators; implement strict input validation requiring permission values to match the regex ^[0-7]{3,4}$ before processing; log all chmod API requests for audit purposes.How to check if you are affected
- Step 1: Check installed PHP version with: php -v
- Step 2: Verify FileGator installation location and version with: grep -r 'VERSION\|version' /path/to/filegator/ | grep -i '7\.14'
- Step 3: Search web server logs for POST requests to '/chmoditems' API endpoint: grep -i 'chmoditems' /var/log/nginx/access.log or /var/log/apache2/access.log
- Step 4: After patching, confirm FileGator is updated to 7.14.2+ by checking: cat /path/to/filegator/CHANGELOG.md | head -20 or reviewing the git commit hash in version control
FAQ
What is CVE-2026-63358?
A privilege escalation vulnerability in FileGator's /chmoditems API endpoint that allows authenticated users to bypass permission validation and modify file permissions with arbitrary Unix values, potentially escalating to root access.
Is CVE-2026-63358 being actively exploited?
No, this vulnerability is not currently listed on the CISA KEV catalog and no public exploit code has been released.
What versions of PHP are affected by CVE-2026-63358?
FileGator versions up to and including 7.14.1 are affected; version 7.14.2 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-63358?
Run: grep -i 'version' /path/to/filegator/package.json or check your FileGator admin panel for the version number; if it is below 7.14.2, your system is vulnerable.
Does Defensia detect CVE-2026-63358?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP and FileGator are installed on a monitored server, CVE-2026-63358 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
- https://github.com/filegator/filegator/blob/master/CHANGELOG.md#7142---2026-05-18
- https://github.com/filegator/filegator/commit/4a44ed9a43f84505703dce669c68fb55270c3f2c
- https://github.com/filegator/filegator/tree/master
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-03.json
- https://www.cve.org/CVERecord?id=CVE-2026-63358
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-63358. Free for 1 server.
Get started free