Authentication Bypass in FileBrowser on Case-Insensitive Filesystems
CVE-2026-72836
9.2CRITICAL
What is CVE-2026-72836?
FileBrowser versions prior to 2.63.19 are susceptible to an authentication bypass vulnerability stemming from improper case sensitivity checks on file ownership. When installed on a case-insensitive filesystem, such as Windows with NTFS, self-registered usernames differing only in letter case can lead to the same physical home directory being shared among distinct accounts. This mismanagement allows attackers to read, overwrite, and delete files belonging to other users without their consent, solely through authenticated endpoints, posing significant risks to user data security.
Affected Version(s)
filebrowser 0 < 2.63.19
filebrowser 2.63.19
