Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Incorrect Access Control in Filestash 0.4.0 |
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Incorrect Access Control in Filestash 0.4.0 |
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 16 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filestash
Filestash filestash |
|
| Vendors & Products |
Filestash
Filestash filestash |
Mon, 15 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-16T18:06:51.330Z
Reserved: 2026-06-07T00:00:00.000Z
Link: CVE-2026-50891
Updated: 2026-06-16T18:06:40.745Z
Status : Deferred
Published: 2026-06-15T20:16:32.110
Modified: 2026-06-16T19:17:00.440
Link: CVE-2026-50891
No data.
OpenCVE Enrichment
Updated: 2026-06-17T23:15:14Z