CVE Feed

    Dashboard / CVE / CVE-2026-10031

    CVE-2026-10031

    SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.

    Published:Jul 30, 2026
    Last Modified:Aug 14, 2026
    EPS:Jul 30, 2026
    EPSS Score:0.00181
    CVSS Score:4.2

    Affected Products

    Vendor
    Drakkan
    Product
    Sftpgo
    Vendor
    Sftpgo Project
    Product
    Sftpgo

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High