Description
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Published: 2026-08-28
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted access to shared files through exposed public links
Action: Apply Patch
AI Analysis

Impact

File Browser versions 2.63.6 through 2.63.23 exhibit a flaw where public share links are not cleaned up after a privileged user deletes another user's shared file. This allows attackers to use the stale link to download any new content uploaded to the same directory, bypassing authentication. The weakness corresponds to error handling failure (CWE-459) and results in unauthorized disclosure of data held in shared files.

Affected Systems

The affected product is File Browser from the vendor filebrowser, specifically the filebrowser: filebrowser. Vulnerable releases range from 2.63.6 up to and including 2.63.23. Users running any of these versions should review their deployment for the presence of public share links.

Risk and Exploitability

The CVSS score is 2.3, indicating low severity. EPSS data is not available and this issue is not listed in CISA’s KEV catalog. An attacker needs privileged rights to delete files owned by other users; once a privileged account performs such a deletion, the remaining share link can grant unauthenticated access to files uploaded thereafter. Because the flaw depends on privileged actions, the overall risk is limited by the privileged user base, but the impact on confidentiality for each exposed link remains significant.

Generated by OpenCVE AI on August 28, 2026 at 14:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade File Browser to a version that includes the fix for share link cleanup.
  • If an upgrade cannot be performed immediately, restrict privileged users so they can delete only their own files or disable public sharing for files that are deleted.
  • Manually revoke any active public share links that may still exist after a file deletion to prevent accidental exposure until the patch is applied.

Generated by OpenCVE AI on August 28, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Title File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion
First Time appeared Filebrowser
Filebrowser filebrowser
Weaknesses CWE-459
CPEs cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*
Vendors & Products Filebrowser
Filebrowser filebrowser
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T14:49:07.319Z

Reserved: 2026-08-28T10:37:04.620Z

Link: CVE-2026-82236

cve-icon Vulnrichment

Updated: 2026-08-28T14:49:02.952Z

cve-icon NVD

Status : Received

Published: 2026-08-28T12:16:33.420

Modified: 2026-08-28T16:18:32.290

Link: CVE-2026-82236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:00:13Z

Weaknesses