Authentication Bypass in FileBrowser on Case-Insensitive Filesystems
CVE-2026-72836

9.2CRITICAL

Key Information:

Vendor
CVE Published:
14 August 2026

What is CVE-2026-72836?

FileBrowser versions prior to 2.63.19 are susceptible to an authentication bypass vulnerability stemming from improper case sensitivity checks on file ownership. When installed on a case-insensitive filesystem, such as Windows with NTFS, self-registered usernames differing only in letter case can lead to the same physical home directory being shared among distinct accounts. This mismanagement allows attackers to read, overwrite, and delete files belonging to other users without their consent, solely through authenticated endpoints, posing significant risks to user data security.

Affected Version(s)

filebrowser 0 < 2.63.19

filebrowser 2.63.19

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

luoy16002-svg
hacdias
.