{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/file-browser--2.63.22/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-73612"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["File Browser (\u003c 2.63.22)","filebrowser (\u003c 2.63.19)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","access-control-bypass","cve","file-deletion","path-traversal"],"_cs_type":"advisory","_cs_vendors":["File Browser","FileBrowser"],"content_html":"\u003cp\u003eFile Browser versions prior to 2.63.22 are affected by an authorization bypass vulnerability stemming from a flaw in how the application validates access rules during recursive file operations. Authenticated users with limited permissions to a parent directory can circumvent access control rules to perform unauthorized actions on descendant files or directories. The vulnerability manifests during copy, rename, and delete operations, where the system fails to verify that the target files or destination paths adhere to the organization's defined access constraints. This allows a low-privileged user to impact the confidentiality and integrity of restricted files by initiating recursive commands from a parent folder for which they have valid access. This issue is tracked as CVE-2026-73612 and carries a CVSS base score of 8.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to bypass path-based access controls, potentially leading to unauthorized data exfiltration (via copy), unauthorized data destruction (via delete), or directory structure manipulation (via rename). This can result in significant loss of confidentiality and integrity for files that were intended to be protected by administrative or user-based access rules.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade File Browser installations to version 2.63.22 or later to remediate the authorization logic flaw identified in CVE-2026-73612.\u003c/li\u003e\n\u003cli\u003eAudit current access control rules within the File Browser environment to identify any over-privileged user roles that could facilitate this attack.\u003c/li\u003e\n\u003cli\u003eMonitor file management logs for anomalous patterns of recursive copy, move, or delete operations originating from low-privileged accounts or unexpected directory paths.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-13T12:55:42Z","date_published":"2026-08-13T12:55:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-file-browser-access-bypass/","summary":"File Browser versions prior to 2.63.22 contain an authorization bypass vulnerability allowing authenticated users to manipulate restricted files via recursive copy, rename, and delete operations.","title":"Authorization Bypass in File Browser via Recursive Operations","url":"https://feed.craftedsignal.io/briefs/2026-08-file-browser-access-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - File Browser (\u003c 2.63.22)","version":"https://jsonfeed.org/version/1.1"}