Timing Attack Vulnerability in FileBrowser Quantum by GT Steffaniak
CVE-2026-54685
5.3MEDIUM
What is CVE-2026-54685?
FileBrowser Quantum, a web-based file management tool, is susceptible to a timing attack due to its /api/auth/login endpoint not being executed in constant time. The authentication process exhibits a significant delay when a valid username is provided, enabling attackers to infer valid usernames through response timing analysis. This vulnerability has been addressed in version 1.3.2-beta, which implements improvements to ensure consistent response time, thereby mitigating the risk.
Affected Version(s)
filebrowser < 1.3.2-beta
