Description
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment. | |
| Title | File Browser before 2.63.20 Privilege Escalation via Proxy Authentication | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:42.191Z
Reserved: 2026-08-10T15:13:41.486Z
Link: CVE-2026-72837
No data.
Status : Received
Published: 2026-08-14T12:16:47.187
Modified: 2026-08-14T12:16:47.187
Link: CVE-2026-72837
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-284
Improper Access Control