Skip to content
Threat Feed

Tag

File-Browser

4 briefs RSS
high advisory

Improper Authorization in File Browser Direct-Upload Endpoint

File Browser versions 2.5.0 through 2.63.23 are vulnerable to an improper authorization flaw allowing authenticated users to trigger recursive directory deletion via the direct-upload endpoint.

File Browser cve-2026-90929 improper-authorization file-browser impact vulnerability
1r 1t 1c
medium advisory

File Browser Symlink Following Vulnerability Allows Out-of-Scope File Deletion (CVE-2026-55667)

A File Browser user with only `Create` permission can exploit CVE-2026-55667, an incomplete fix for CVE-2026-54094, to delete arbitrary files and directories outside their authorized scope by abusing the `ScopedFs.RemoveAll` function's symlink-following behavior during failed upload cleanup, leading to data loss, cross-tenant data deletion, or denial of service.

filebrowser vulnerability file-browser symlink-attack data-loss denial-of-service
2t 2c
high advisory

FileBrowser Authentication Bypass via Forged Proxy Authentication Header

An unauthenticated attacker can impersonate any user, including administrators, or automatically create new user accounts in FileBrowser by forging the `X-Remote-User` HTTP header when the server is configured for proxy authentication and is directly reachable, leading to full administrative control and unauthorized access to data.

FileBrowser authentication-bypass web-vulnerability privilege-escalation file-browser account-creation
1r 3t
high advisory

File Browser Proxy Authentication Bypass Vulnerability (CVE-2026-35607)

File Browser versions before 2.63.1 improperly grant execution capabilities to new users created via proxy authentication, leading to privilege escalation.

File Browser file-browser authentication-bypass privilege-escalation cve-2026-35607
2r 1t 1c