File Management Interface Vulnerability in File Browser by FileBrowser
CVE-2026-35606
5.3MEDIUM
What is CVE-2026-35606?
The File Browser product, prior to version 2.63.1, contains a vulnerability in its resource handling that permits unauthorized users to access full text file content without appropriate permission checks. Specifically, the resourceGetHandler does not verify the necessary Perm.Download flag, enabling users with 'download: false' authority to bypass security and read any text files within their designated scope. This issue is present across multiple endpoints, although the others correctly enforce permission validation, posing a significant risk that has since been addressed in the 2.63.1 update.
Affected Version(s)
filebrowser < 2.63.1
