Directory Traversal Vulnerability in FileBrowser Quantum by GT Steffaniak
CVE-2026-44542

9.1CRITICAL

Key Information:

Vendor
CVE Published:
14 May 2026

What is CVE-2026-44542?

FileBrowser Quantum, a self-hosted web-based file manager, is susceptible to a directory traversal vulnerability. Attackers can manipulate path input, which is improperly joined with a trusted base path before sanitization. This flaw allows unauthorized access to files outside the intended directory, potentially deleting arbitrary files if the attacker possesses a valid public share hash with delete permissions. Affected endpoints include public/api/resources and public/api/resources/bulk. This vulnerability has been addressed in versions 1.3.1-stable and 1.3.9-beta.

Affected Version(s)

filebrowser < 1.3.1-stable < 1.3.1-stable

filebrowser < 1.3.9-beta < 1.3.9-beta

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.