Impact
An unauthenticated attacker can use the self‑signup feature in filebrowser to create a new account that automatically receives full root‑scope permissions, including the ability to create, modify, delete, rename, share, and download any file on the web server. This is a high‑severity privilege escalation flaw as identified by CWE‑266, allowing the attacker to read, alter, or destroy any data stored on the file system.
Affected Systems
The vulnerable product is filebrowser, an open‑source web file management system. All releases up to and including version 2.63.16 allow this flaw. Versions 2.63.17 and later contain the fix. Users running older or patched releases are no longer affected.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability is classified as Critical. EPSS data is not available, but because the flaw does not require any authentication or additional barriers, an attacker can exploit it from any network location that can reach the sign‑up interface. It is not listed in the CISA KEV catalog, yet the combination of a high severity rating and the ease of execution makes it a top priority for remediation. The vulnerability enables unrestricted access to the entire file system, severely compromising confidentiality, integrity, and availability.
OpenCVE Enrichment