CVE-2023-26321: Mi File Manager

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited by attackers to overwrite and execute code in the file.

Affected products

  • Mi File Manager: version 1-210567 only

Published 2024-08-28. Last modified 2026-06-17.