CVE-2026-51027
FileThingie · FileThingie
FileThingie version 2.5.7 contains a vulnerability in the ft2.php component that allows a remote, authenticated attacker to obtain sensitive information from the system.
Executive summary
A vulnerability in FileThingie version 2.5.7 allows an authenticated attacker to perform unauthorized information disclosure, posing a severe risk to data confidentiality.
Vulnerability
The application is susceptible to sensitive information disclosure via the ft2.php component. Per the CVSS vector PR:L, this vulnerability requires the attacker to have low-level privileges (authenticated access) to the application.
Business impact
The exposure of sensitive information can lead to a compromise of system configuration, credentials, or internal data structures. Given the high CVSS score of 9.9, this vulnerability represents a critical threat to organizational security, potentially allowing an attacker to escalate privileges or gain deeper access to the underlying infrastructure.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should restrict access to the ft2.php component or disable the affected functionality until the vendor releases a security update.
Proactive Monitoring: Review web server access logs for unusual patterns or excessive requests targeting the ft2.php file.
Compensating Controls: Implement Web Application Firewall (WAF) rules to filter and block suspicious requests directed at the FileThingie installation.
Exploitation status
Public Exploit Available: No (no confirmed public exploit available).
Analyst recommendation
Due to the critical nature of this vulnerability and the presence of a known proof-of-concept, administrators must prioritize securing their FileThingie instances immediately. Monitor vendor communication channels closely for an official patch release and apply it as soon as it becomes available.