Description
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
Published: 2026-08-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

File Browser versions earlier than 2.63.20 allow an authenticated attacker with upstream credentials to bypass the intended isolation of user directories. The bug occurs because the createUserDir check is ignored in proxy and hook authentication auto‑provisioning paths, letting the attacker read, modify, delete, and share files that belong to other users. This exposes not only the confidentiality of other users’ data but also its integrity and availability, and it facilitates lateral movement within the system.

Affected Systems

The vulnerability affects all deployments of File Browser whose product name is "File Browser" by the vendor "File Browser" where the installed version is earlier than 2.63.20. No specific sub‑components are mentioned beyond the core proxy and hook authentication mechanisms.

Risk and Exploitability

The CVSS score is 8.7, indicating a high‑severity flaw. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, but the ability to elevate privileges from an upstream‑authenticated context makes the vulnerability practically exploitable on systems with exposed proxy authentication. An adversary who compromises or guesses a valid upstream credential can immediately gain the ability to manipulate other users’ files, posing a serious threat in multi‑tenant or shared environments.

Generated by OpenCVE AI on August 14, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade File Browser to version 2.63.20 or later
  • If an upgrade is not immediately possible, disable or tightly restrict proxy authentication for untrusted upstream connections
  • Ensure that configuration or code changes enforce proper isolation of user directories and prevent any cross‑user file access

Generated by OpenCVE AI on August 14, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Filebrowser
Filebrowser filebrowser
Vendors & Products Filebrowser
Filebrowser filebrowser

Fri, 14 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
Title File Browser before 2.63.20 Privilege Escalation via Proxy Authentication
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T16:52:18.149Z

Reserved: 2026-08-10T15:13:41.486Z

Link: CVE-2026-72837

cve-icon Vulnrichment

Updated: 2026-08-14T14:36:10.665Z

cve-icon NVD

Status : Received

Published: 2026-08-14T12:16:47.187

Modified: 2026-08-14T15:17:11.050

Link: CVE-2026-72837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T13:15:17Z

Weaknesses