CVE-2026-29515CRITICAL 9.8EPSS p37.7%

CVE-2026-29515CVE-2026-29515

Description

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows listing, reading, writing, and deleting files exposed by the FTP server. The MiCode/Explorer open source project has reached end-of-life status.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.48% probability of exploitation · percentile 37.7% · 2026-06-18T12:00:27Z
Published2026-03-11
Last modified2026-05-07

Underlying weaknesses· 2

CWE-303CWE-862

References

  1. https://github.com/MiCode/FileExplorer
  2. https://www.vulncheck.com/advisories/micode-fileexplorer-swiftp-server-authentication-bypass

2

TypeTargetConfidenceTier
WeaknessIncorrect Implementation of Authentication Algorithmcwe-3030%live
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-49195
CVE
CVE-2025-5357
CVE
CVE-2025-5053
CVE
Mitel MiCollab Path Traversal Vulnerability
CVE
CVE-2025-5356
CVE
CVE-2025-5295
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.