Vendor
Improper Authorization in File Browser Direct-Upload Endpoint
1 rule 1 TTP 1 CVEFile Browser versions 2.5.0 through 2.63.23 are vulnerable to an improper authorization flaw allowing authenticated users to trigger recursive directory deletion via the direct-upload endpoint.
Authorization Bypass in File Browser via Recursive Operations
1 rule 2 TTPs 1 CVEFile Browser versions prior to 2.63.22 contain an authorization bypass vulnerability allowing authenticated users to manipulate restricted files via recursive copy, rename, and delete operations.
File Browser Pre-Authentication Command Injection via Authentication Hook (CVE-2026-54088)
1 rule 2 TTPs 1 CVEThe Hook Authentication feature in File Browser (versions up to 2.63.5) is vulnerable to a pre-authentication command injection flaw (CVE-2026-54088), allowing an unauthenticated remote attacker to execute arbitrary OS commands by injecting shell metacharacters into login fields during `os.Expand` operations, leading to critical Remote Code Execution (RCE) without valid credentials.
File Browser Proxy Authentication Bypass Vulnerability (CVE-2026-35607)
2 rules 1 TTP 1 CVEFile Browser versions before 2.63.1 improperly grant execution capabilities to new users created via proxy authentication, leading to privilege escalation.