CVE-2026-51027

FileThingie · FileThingie

FileThingie version 2.5.7 contains a vulnerability in the ft2.php component that allows a remote, authenticated attacker to obtain sensitive information from the system.

Executive summary

A vulnerability in FileThingie version 2.5.7 allows an authenticated attacker to perform unauthorized information disclosure, posing a severe risk to data confidentiality.

Vulnerability

The application is susceptible to sensitive information disclosure via the ft2.php component. Per the CVSS vector PR:L, this vulnerability requires the attacker to have low-level privileges (authenticated access) to the application.

Business impact

The exposure of sensitive information can lead to a compromise of system configuration, credentials, or internal data structures. Given the high CVSS score of 9.9, this vulnerability represents a critical threat to organizational security, potentially allowing an attacker to escalate privileges or gain deeper access to the underlying infrastructure.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should restrict access to the ft2.php component or disable the affected functionality until the vendor releases a security update.

Proactive Monitoring: Review web server access logs for unusual patterns or excessive requests targeting the ft2.php file.

Compensating Controls: Implement Web Application Firewall (WAF) rules to filter and block suspicious requests directed at the FileThingie installation.

Exploitation status

Public Exploit Available: No (no confirmed public exploit available).

Analyst recommendation

Due to the critical nature of this vulnerability and the presence of a known proof-of-concept, administrators must prioritize securing their FileThingie instances immediately. Monitor vendor communication channels closely for an official patch release and apply it as soon as it becomes available.