CVE-2026-50891High· 8.1▾ TwilightFilestash allows attackers to escalate privileges via sending a crafted request
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.
github.com/mickael-kerjean/filestash <= 0.2.2-0.20260827111952-cbcd1e96ebc7Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.