PT-2026-24573 · Unknown · Swiftp Ftp Server+1

Vulncheck

+1

·

Published

2026-03-11

·

Updated

2026-05-11

·

CVE-2026-29515

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MiCode FileExplorer (affected versions not specified)
Description The software contains an authentication bypass in the embedded SwiFTP FTP server component. This allows network attackers to log in without valid credentials by sending arbitrary username and password combinations to the PASS command handler, which unconditionally grants access. Successful exploitation allows attackers to list, read, write, and delete files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-29515

Affected Products

Micode Fileexplorer
Swiftp Ftp Server