SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-51027

CRITICAL · CVSS 9.9 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

FileThingie v2.5.7 is vulnerable due to a flaw in the ft2.php component that allows remote attackers to access sensitive information. This critical vulnerability, rated 9.9 on the CVSS scale, poses a significant risk to any organization using this version of the software. Organizations currently utilizing FileThingie should prioritize immediate remediation to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51027
Severity
CRITICAL
CVSS
9.9
EPSS
0.34%

Original NVD Description

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.