Description
filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope. | |
| Title | filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization | |
| Weaknesses | CWE-41 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:40.774Z
Reserved: 2026-08-10T15:13:41.486Z
Link: CVE-2026-72835
No data.
Status : Received
Published: 2026-08-14T12:16:46.930
Modified: 2026-08-14T12:16:46.930
Link: CVE-2026-72835
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-41
Improper Resolution of Path Equivalence