1.
projectblack.io | vulnerability | Medium | | original ↗ | #access-control | #privilege-escalation | #web-security | #liquidfiles
A secondary-domain admin in LiquidFiles can escalate to sysadmin (CVE-2026-12673) by tampering with group requests to set admin_level=5. The post walks through the exploitation and the vendor's fix.
Skip to content