CVE Record
[ HIGH ]CVE-2026-19979
GL.iNet WebDAV COPY/MOVE authorization bypass allows out-of-scope file access
Authorization bypass in GL.iNet's WebDAV service COPY and MOVE operations lets remote attackers access files outside the designated public share scope on a wide range of 4.8.x devices.
- Vendor
- GL.iNet
- Product
- A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
- CVSS
- 8.3
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
The WebDAV service on affected GL.iNet devices fails to enforce destination-path authorization checks on COPY and MOVE operations. A remote attacker can redirect file operations to paths outside the intended public-share directory, bypassing the share boundary.
GL.iNet confirmed the issue and released firmware 4.9.0 as the fix. Public proof-of-concept code is available. See the full GL.iNet advisory batch for all five patched vulnerabilities.
