Skip to content
Threat Feed

Vendor

File Browser

4 briefs RSS
high advisory

Improper Authorization in File Browser Direct-Upload Endpoint

File Browser versions 2.5.0 through 2.63.23 are vulnerable to an improper authorization flaw allowing authenticated users to trigger recursive directory deletion via the direct-upload endpoint.

File Browser cve-2026-90929 improper-authorization file-browser impact vulnerability
1r 1t 1c
critical advisory

Authorization Bypass in File Browser via Recursive Operations

File Browser versions prior to 2.63.22 contain an authorization bypass vulnerability allowing authenticated users to manipulate restricted files via recursive copy, rename, and delete operations.

File Browser +2 vulnerability access-control-bypass cve file-deletion path-traversal
1r 2t 1c updated
critical advisory

File Browser Pre-Authentication Command Injection via Authentication Hook (CVE-2026-54088)

The Hook Authentication feature in File Browser (versions up to 2.63.5) is vulnerable to a pre-authentication command injection flaw (CVE-2026-54088), allowing an unauthenticated remote attacker to execute arbitrary OS commands by injecting shell metacharacters into login fields during `os.Expand` operations, leading to critical Remote Code Execution (RCE) without valid credentials.

File Browser command-injection rce web-application
1r 2t 1c
high advisory

File Browser Proxy Authentication Bypass Vulnerability (CVE-2026-35607)

File Browser versions before 2.63.1 improperly grant execution capabilities to new users created via proxy authentication, leading to privilege escalation.

File Browser file-browser authentication-bypass privilege-escalation cve-2026-35607
2r 1t 1c