Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available.
Published: 2026-07-20
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FileBrowser Quantum is a free, self-hosted, web‑based file manager. In versions before 1.3.2‑stable and 1.4.1‑beta, an unauthenticated user can query the share endpoint and obtain detailed share metadata, including the source and path of files. This allows an attacker to discover sensitive internal directory structure and other file information that could be leveraged for further attacks.

Affected Systems

The affected product is FileBrowser Quantum developed by the github user gtsteffaniak. Versions prior to 1.3.2-stable and 1.4.1-beta are vulnerable. Users running these releases need to assess the environment to determine whether share information is exposed to the internet.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity and a high likelihood of exploitation if the web service is exposed. The EPSS score is less than 1%, indicating a low probability of exploitation in the general population, but the vulnerability remains a concern for exposed instances. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote unauthenticated access via the web interface; an attacker only needs to know the URL of the file share endpoint, which is typically publicly reachable if the instance is not behind authentication or a firewall. Once accessed, the attacker can enumerate files and directories, increasing the risk of further compromise.

Generated by OpenCVE AI on July 30, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to FileBrowser Quantum version 1.3.2-stable or later, or 1.4.1-beta or later, which contain the fix for share information disclosure.
  • If an upgrade cannot be performed immediately, restrict access to the share endpoint by placing the web service behind a firewall or reverse proxy that requires authentication, or by blocking the share endpoint URL from unauthenticated clients.
  • If the share feature is not required, disable it in the FileBrowser configuration to eliminate the exposed endpoint.

Generated by OpenCVE AI on July 30, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3jmg-p96m-m328 FileBrowser Quantum: unauthenticated user share share info
History

Tue, 21 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Gtsteffaniak
Gtsteffaniak filebrowser
Vendors & Products Gtsteffaniak
Gtsteffaniak filebrowser

Mon, 20 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available.
Title FileBrowser Quantum: unauthenticated user share share info
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Gtsteffaniak Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-21T14:10:48.573Z

Reserved: 2026-05-13T21:04:10.933Z

Link: CVE-2026-46410

cve-icon Vulnrichment

Updated: 2026-07-21T14:10:43.009Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor