Permission Bypass in Filebrowser Affects Access Control for Download Permissions
CVE-2026-72834
5.3MEDIUM
What is CVE-2026-72834?
The Filebrowser application prior to version 2.63.19 has a significant vulnerability that allows an authenticated user to bypass permission checks on the /api/resources endpoint. Specifically, the resourceGetHandler's handling of checksums allows users with restricted permission (Perm.Download=false) to access file content hashes. This oversight enables the user to confirm the presence of particular files, detect changes in content, and potentially execute offline brute-force attacks on low-entropy files. This vulnerability also highlights the incomplete remediation of a previous issue, providing insights into the necessity for more robust access control mechanisms.
Affected Version(s)
filebrowser 0 < 2.63.19
filebrowser 2.63.19
