Timing Attack Vulnerability in FileBrowser Quantum by GT Steffaniak
CVE-2026-54685

5.3MEDIUM

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-54685?

FileBrowser Quantum, a web-based file management tool, is susceptible to a timing attack due to its /api/auth/login endpoint not being executed in constant time. The authentication process exhibits a significant delay when a valid username is provided, enabling attackers to infer valid usernames through response timing analysis. This vulnerability has been addressed in version 1.3.2-beta, which implements improvements to ensure consistent response time, thereby mitigating the risk.

Affected Version(s)

filebrowser < 1.3.2-beta

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.