File Management Interface Vulnerability in File Browser by File Browser
CVE-2026-62684
2.7LOW
What is CVE-2026-62684?
A vulnerability in File Browser prior to version 2.63.17 allows for the serialization of sensitive data, specifically the password_hash and bypass token. This occurs through the sharePostHandler, shareListHandler, and shareGetsHandler when handling requests via POST and GET methods for shared files. Consequently, an administrator can access these secrets for all user shares, leading to potential offline password cracking efforts and unauthorized access to protected file shares. Users are advised to update to version 2.63.17 to mitigate this risk.
Affected Version(s)
filebrowser < 2.63.17
