PT-2026-61697 · Unknown · Filecodebox

·

CVE-2026-64619

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FileCodeBox versions prior to 2.4
Description A rate-limit bypass exists in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling. This occurs because the system does not verify the origin of trusted reverse proxies when processing the X-Real-IP and X-Forwarded-For headers. By supplying unique spoofed IP values in these headers for each request, an attacker can enumerate share codes and retrieve files belonging to other users without authentication.
Recommendations Update to version 2.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64619

Affected Products

Filecodebox