CVE-2026-34745 is a critical unauthenticated arbitrary file write vulnerability affecting shaneisrael Fireshare versions prior to 1.5.3. This flaw allows an attacker to write arbitrary files with controlled content to any writable server path via the /api/uploadChunked/public endpoint. Rated 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H), it presents a low-complexity network attack vector requiring no authentication or user interaction, posing a significant risk to system integrity and availability. While there is no known active exploitation or public exploit code available, the vulnerability has garnered community attention with critical alerts on social media. Organizations using Fireshare should upgrade to version 1.5.3 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.3CPE matchmatch criteria | cpe:2.3:a:shaneisrael:fireshare:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.