OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-54337

CRITICAL · CVSS 9.8 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Fireshare versions prior to 1.6.14 are vulnerable to an argument injection flaw in the video upload function, enabling unauthenticated attackers to write or overwrite system files. This critical vulnerability poses a significant risk to systems running affected versions, potentially leading to unauthorized access and system compromise. Organizations using Fireshare should prioritize upgrading to version 1.6.14 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54337
Severity
CRITICAL
CVSS
9.8
EPSS
0.63%

Original NVD Description

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.