File Browser File Management Interface Bug in File Handling By File Browser
CVE-2026-35607

8.1HIGH

Key Information:

Vendor
CVE Published:
7 April 2026

What is CVE-2026-35607?

A vulnerability in the File Browser's file management interface allows users created via the proxy authentication handler to inherit execution permissions unintentionally. Prior to version 2.63.1, the fix applied to self-registered users did not encompass those auto-created accounts, thereby granting them elevated capabilities that could lead to unauthorized file execution. This oversight poses significant security risks, necessitating proactive updates to mitigate potential exploitation.

Affected Version(s)

filebrowser < 2.63.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.