File Management Interface Vulnerability in File Browser by File Browser
CVE-2026-54091
7.5HIGH
What is CVE-2026-54091?
File Browser, a tool designed for managing files, has a vulnerability that allows unauthorized access to blocked files within shared directories. Prior to version 2.63.6, the public share handlers compromised the filesystem's access control by rebasing the owner's root to the shared directory. Attackers could exploit this by using known share URLs to access files and subdirectories explicitly restricted by the owner's rules. This flaw results in serious information disclosure vulnerabilities, exposing sensitive data through unauthenticated requests.
Affected Version(s)
filebrowser < 2.63.6
