Description
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
Published: 2026-07-12
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

filebrowser versions before 2.63.17 allow an authenticated user to delete a shared directory by supplying a path that ends with a trailing slash, causing the stale public share URL to expose new content that was not intended for public access. This results in unauthorized viewing of files or directories that were previously private, potentially leading to data leakage. The flaw is a path normalization failure, classified as CWE-863.

Affected Systems

The affected product is filebrowser from the filebrowser vendor. All released versions of filebrowser earlier than 2.63.17 contain this flaw; no finer version granularity is documented.

Risk and Exploitability

The CVSS score of 2.3 indicates a low severity impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and able to delete and recreate directories; the likely attack vector is an internal user or compromised account. Successful exploitation would provide information disclosure rather than code execution or privilege escalation.

Generated by OpenCVE AI on August 1, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade filebrowser to version 2.63.17 or newer.
  • Ensure that the application automatically removes or invalidates stale public share entries when a directory is deleted.
  • Disable automatic persistence of public shares or require explicit user confirmation before creating a share.

Generated by OpenCVE AI on August 1, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Filebrowser
Filebrowser filebrowser
Vendors & Products Filebrowser
Filebrowser filebrowser

Sun, 12 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
Title filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T22:03:44.276Z

Reserved: 2026-07-10T21:54:26.760Z

Link: CVE-2026-61874

cve-icon Vulnrichment

Updated: 2026-07-13T15:40:10.600Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses