File Management Interface Vulnerability in File Browser by FileBrowser
CVE-2026-54094
7.5HIGH
What is CVE-2026-54094?
The File Browser file management interface allows users to upload, delete, preview, rename, and edit files within a specific directory. However, earlier versions (before 2.63.14) did not properly prevent HTTP file handlers from following symbolic links, potentially allowing a scoped user or even an unauthenticated public-share recipient to access files outside their designated scope. This could lead to unauthorized data exposure by following symlinks that point to locations beyond the user's intended access. The vulnerability has been patched in version 2.63.14, effectively closing this potential exploit.
Affected Version(s)
filebrowser < 2.63.14
