File Execution Vulnerability in File Browser by FileBrowser
CVE-2026-34528
8.1HIGH
What is CVE-2026-34528?
The File Browser file management interface exposes a significant security risk due to improper default user permissions. In versions prior to 2.62.2, the signupHandler fails to adequately restrict permissions for newly registered users. When an administrator has enabled self-registration and server-side execution with Execute set to true, unauthenticated users can self-register and inherit shell execution capabilities. This flaw permits unauthorized execution of arbitrary commands on the server. Users are strongly advised to upgrade to version 2.62.2 or later to mitigate this vulnerability.
Affected Version(s)
filebrowser < 2.62.2
