File Management Interface Vulnerability in File Browser by FileBrowser
CVE-2026-54094

7.5HIGH

Key Information:

Vendor
CVE Published:
25 June 2026

What is CVE-2026-54094?

The File Browser file management interface allows users to upload, delete, preview, rename, and edit files within a specific directory. However, earlier versions (before 2.63.14) did not properly prevent HTTP file handlers from following symbolic links, potentially allowing a scoped user or even an unauthenticated public-share recipient to access files outside their designated scope. This could lead to unauthorized data exposure by following symlinks that point to locations beyond the user's intended access. The vulnerability has been patched in version 2.63.14, effectively closing this potential exploit.

Affected Version(s)

filebrowser < 2.63.14

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.