File Browser Privilege Escalation Vulnerability in Authenticated Sessions
CVE-2026-72837
8.7HIGH
What is CVE-2026-72837?
A critical vulnerability in File Browser versions prior to 2.63.20 allows attackers with valid upstream-authenticated credentials to bypass createUserDir isolation and exploit authentication auto-provisioning paths. This weakness enables unauthorized access to read, modify, delete, and share files belonging to other users, jeopardizing the integrity of user data and overall system security.
Affected Version(s)
filebrowser 0 < 2.63.20
filebrowser 2.63.20
