CVE-2026-29515

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Mar 2026, 13:52

Type Values Removed Values Added
Summary
  • (es) MiCode FileExplorer contiene una vulnerabilidad de omisión de autenticación en el componente de servidor FTP SwiFTP incrustado que permite a los atacantes de red iniciar sesión sin credenciales válidas. Los atacantes pueden enviar combinaciones arbitrarias de nombre de usuario y contraseña al gestor del comando PASS, que concede acceso incondicionalmente y permite listar, leer, escribir y eliminar archivos expuestos por el servidor FTP.

11 Mar 2026, 05:18

Type Values Removed Values Added
Summary (en) MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. (en) MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.

11 Mar 2026, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 04:17

Updated : 2026-03-11 13:52


NVD link : CVE-2026-29515

Mitre link : CVE-2026-29515

CVE.ORG link : CVE-2026-29515


JSON object : View

Products Affected

No product.

CWE
CWE-303

Incorrect Implementation of Authentication Algorithm