<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Filebrowser (&lt; 2.63.19) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/filebrowser--2.63.19/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 12:55:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/filebrowser--2.63.19/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in File Browser via Recursive Operations</title><link>https://feed.craftedsignal.io/briefs/2026-08-file-browser-access-bypass/</link><pubDate>Thu, 13 Aug 2026 12:55:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-file-browser-access-bypass/</guid><description>File Browser versions prior to 2.63.22 contain an authorization bypass vulnerability allowing authenticated users to manipulate restricted files via recursive copy, rename, and delete operations.</description><content:encoded><![CDATA[<p>File Browser versions prior to 2.63.22 are affected by an authorization bypass vulnerability stemming from a flaw in how the application validates access rules during recursive file operations. Authenticated users with limited permissions to a parent directory can circumvent access control rules to perform unauthorized actions on descendant files or directories. The vulnerability manifests during copy, rename, and delete operations, where the system fails to verify that the target files or destination paths adhere to the organization's defined access constraints. This allows a low-privileged user to impact the confidentiality and integrity of restricted files by initiating recursive commands from a parent folder for which they have valid access. This issue is tracked as CVE-2026-73612 and carries a CVSS base score of 8.1.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users to bypass path-based access controls, potentially leading to unauthorized data exfiltration (via copy), unauthorized data destruction (via delete), or directory structure manipulation (via rename). This can result in significant loss of confidentiality and integrity for files that were intended to be protected by administrative or user-based access rules.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade File Browser installations to version 2.63.22 or later to remediate the authorization logic flaw identified in CVE-2026-73612.</li>
<li>Audit current access control rules within the File Browser environment to identify any over-privileged user roles that could facilitate this attack.</li>
<li>Monitor file management logs for anomalous patterns of recursive copy, move, or delete operations originating from low-privileged accounts or unexpected directory paths.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>access-control-bypass</category><category>cve</category><category>file-deletion</category><category>path-traversal</category></item></channel></rss>