SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-51026

MEDIUM · CVSS 6.5 EPSS 0.85% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

FileThingie version 2.5.7 is vulnerable to a directory traversal attack, enabling remote attackers to access sensitive information through specially crafted requests. This vulnerability poses a medium risk, and organizations using this software should prioritize remediation to protect against potential data exposure. Security teams should assess their environments for the presence of this version and implement necessary updates or mitigations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51026
Severity
MEDIUM
CVSS
6.5
EPSS
0.85%

Original NVD Description

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.