Remote Command Execution in File Browser by FileBrowser
CVE-2026-54088
9.3CRITICAL
What is CVE-2026-54088?
File Browser, a widely used file management tool, contains a vulnerability in its Hook Authentication feature that allows unchecked execution of external shell commands. Prior to version 2.63.6, an unauthenticated attacker could exploit this flaw by injecting malicious input into the username or password fields during the login process. As a result, this could lead to arbitrary OS command execution on the server, compromising the security of the entire system. It is crucial for users to upgrade to the latest version to mitigate this significant risk.
Affected Version(s)
filebrowser < 2.63.6
