Permission Bypass in Filebrowser Affects Access Control for Download Permissions
CVE-2026-72834

5.3MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2026

What is CVE-2026-72834?

The Filebrowser application prior to version 2.63.19 has a significant vulnerability that allows an authenticated user to bypass permission checks on the /api/resources endpoint. Specifically, the resourceGetHandler's handling of checksums allows users with restricted permission (Perm.Download=false) to access file content hashes. This oversight enables the user to confirm the presence of particular files, detect changes in content, and potentially execute offline brute-force attacks on low-entropy files. This vulnerability also highlights the incomplete remediation of a previous issue, providing insights into the necessity for more robust access control mechanisms.

Affected Version(s)

filebrowser 0 < 2.63.19

filebrowser 2.63.19

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
hacdias
.