Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-19979

GL.iNet WebDAV COPY/MOVE authorization bypass allows out-of-scope file access

Authorization bypass in GL.iNet's WebDAV service COPY and MOVE operations lets remote attackers access files outside the designated public share scope on a wide range of 4.8.x devices.

cat cve-2026-19979.json
Vendor
GL.iNet
Product
A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVSS
8.3
EPSS (exploit probability)
0.4%
Status
patched
Published

The WebDAV service on affected GL.iNet devices fails to enforce destination-path authorization checks on COPY and MOVE operations. A remote attacker can redirect file operations to paths outside the intended public-share directory, bypassing the share boundary.

GL.iNet confirmed the issue and released firmware 4.9.0 as the fix. Public proof-of-concept code is available. See the full GL.iNet advisory batch for all five patched vulnerabilities.