File Management Interface Vulnerability in File Browser by File Browser
CVE-2026-62684

2.7LOW

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-62684?

A vulnerability in File Browser prior to version 2.63.17 allows for the serialization of sensitive data, specifically the password_hash and bypass token. This occurs through the sharePostHandler, shareListHandler, and shareGetsHandler when handling requests via POST and GET methods for shared files. Consequently, an administrator can access these secrets for all user shares, leading to potential offline password cracking efforts and unauthorized access to protected file shares. Users are advised to update to version 2.63.17 to mitigate this risk.

Affected Version(s)

filebrowser < 2.63.17

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.