Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-19979

GL.iNet WebDAV COPY/MOVE authorization bypass allows out-of-scope file access

Authorization bypass in GL.iNet's WebDAV service COPY and MOVE operations lets remote attackers access files outside the designated public share scope on a wide range of 4.8.x devices.

cat cve-2026-19979.json
Vendor
GL.iNet
Product
A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVSS
8.3
EPSS (exploit probability)
N/A
Status
patched
Published

The WebDAV service on affected GL.iNet devices fails to enforce destination-path authorization checks on COPY and MOVE operations. A remote attacker can redirect file operations to paths outside the intended public-share directory, bypassing the share boundary.

GL.iNet confirmed the issue and released firmware 4.9.0 as the fix. Public proof-of-concept code is available. See the full GL.iNet advisory batch for all five patched vulnerabilities.