Impact
This vulnerability arises from a missing path canonicalization step in filebrowser before v2.63.21. Users who authenticate can craft path strings that differ in case or use backslashes, which the engine interprets the same after path resolution but bypasses the predefined deny rules. As a result, an attacker can request files that are otherwise protected and obtain unauthorized read access.
Affected Systems
Affected versions are all releases of filebrowser before 2.63.21. The vulnerability applies to installations that use the default access rule configuration and authenticate users, regardless of the underlying operating system. No specific operating system or deployment type is limited.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity and an authenticated attack is required. Because no EPSS score is available, the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Attackers can manipulate path representations to circumvent rules, so the exploitation risk remains significant for systems exposed to authenticated users with file access permissions.
OpenCVE Enrichment