[CVE-2026-12673] Liquidfiles Privilege Escalation
projectblack.io | vulnerability | Medium | CVE-2026-12673 | #access-control | #privilege-escalation | #web-security | #liquidfiles | #cve-2026-12673
Summary
A secondary-domain admin in LiquidFiles can escalate to sysadmin (CVE-2026-12673) by tampering with group requests to set admin_level=5. The post walks through the exploitation and the vendor's fix.
- CVSS
- 5.9
- Published
- Collected
Skip to content