CVE-2026-62684
- EPSS 0.39%
- Veröffentlicht 18.08.2026 15:20:10
- Zuletzt bearbeitet 18.08.2026 18:18:54
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and share...
CVE-2026-72838
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:42
- Zuletzt bearbeitet 17.08.2026 16:17:45
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the decla...
CVE-2026-72837
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:42
- Zuletzt bearbeitet 14.08.2026 15:17:11
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to ot...
CVE-2026-72836
- EPSS 0.32%
- Veröffentlicht 14.08.2026 11:35:41
- Zuletzt bearbeitet 18.08.2026 02:17:28
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confir...
CVE-2026-72835
- EPSS 0.34%
- Veröffentlicht 14.08.2026 11:35:40
- Zuletzt bearbeitet 14.08.2026 18:19:08
filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with ...
CVE-2026-72834
- EPSS 0.23%
- Veröffentlicht 14.08.2026 11:35:40
- Zuletzt bearbeitet 14.08.2026 15:17:10
filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike t...
CVE-2026-72839
- EPSS 0.39%
- Veröffentlicht 13.08.2026 21:54:39
- Zuletzt bearbeitet 14.08.2026 17:20:31
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, ...
CVE-2026-73613
- EPSS 0.36%
- Veröffentlicht 13.08.2026 11:28:16
- Zuletzt bearbeitet 14.08.2026 21:17:57
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers ca...
CVE-2026-73612
- EPSS 0.27%
- Veröffentlicht 13.08.2026 11:28:15
- Zuletzt bearbeitet 13.08.2026 15:20:19
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by...
CVE-2026-73611
- EPSS 0.27%
- Veröffentlicht 13.08.2026 11:28:15
- Zuletzt bearbeitet 14.08.2026 23:16:33
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints...