{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afilebrowserfilebrowser/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-90929"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["File Browser (\u003e= 2.5.0 and \u003c= 2.63.23)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-90929","improper-authorization","file-browser","impact","vulnerability"],"_cs_type":"advisory","_cs_vendors":["File Browser"],"content_html":"\u003cp\u003eFile Browser versions 2.5.0 through 2.63.23 contain an incorrect authorization flaw within the direct-upload endpoint, specifically located in the resourcePostHandler function of http/resource.go. The vulnerability allows an authenticated user with standard Create and Modify permissions to initiate a recursive deletion of directories they are not authorized to remove. When a POST request with the override=true parameter is sent to an existing directory, the application attempts to open the directory for writing. This operation fails, triggering a cleanup path that executes Fs.RemoveAll on the request path. Crucially, this cleanup routine bypasses the standard Perm.Delete permission check and the checkDescendants rule walk, leading to unintended file system modification. While the impact remains confined to the user's defined scope, an attacker can delete directories and files that should be restricted by rule-denied access controls. This vulnerability was introduced in version 2.5.0 and remains unpatched.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the File Browser application with an account possessing only Create and Modify permissions.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a target directory within their scoped environment that contains sensitive or protected files.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious HTTP POST request targeting the direct-upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the query parameter override=true in the request path, pointing to the target directory.\u003c/li\u003e\n\u003cli\u003eThe server-side resourcePostHandler receives the request and attempts to execute a write operation on the target path.\u003c/li\u003e\n\u003cli\u003eThe application fails to write to the directory because it is not a file, triggering the Fs.RemoveAll cleanup mechanism.\u003c/li\u003e\n\u003cli\u003eThe system recursively deletes the target directory and its contents, bypassing standard delete authorization checks.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated, low-privileged users to perform unauthorized recursive deletions of directories and files within their scope. This impact could lead to significant data loss or the removal of rule-denied configuration files, causing disruption to service or access control integrity within the application. The vulnerability affects all users running vulnerable versions (2.5.0 through 2.63.23) and currently lacks a vendor-supplied patch.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of unauthorized deletion attempts within the File Browser application.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict auditing of POST requests to the direct-upload endpoint, specifically flagging those containing the override=true query parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP 500 status codes originating from the direct-upload endpoint that correlate with attempted directory write operations.\u003c/li\u003e\n\u003cli\u003eRestrict access to File Browser instances until a patch is provided by the vendor, as no current mitigation is available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T13:34:05Z","date_published":"2026-09-14T13:34:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90929/","summary":"File Browser versions 2.5.0 through 2.63.23 are vulnerable to an improper authorization flaw allowing authenticated users to trigger recursive directory deletion via the direct-upload endpoint.","title":"Improper Authorization in File Browser Direct-Upload Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90929/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}