FileBrowser Privilege Escalation Vulnerability in Version 2.63.16
CVE-2026-72839

9.3CRITICAL

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-72839?

The FileBrowser application prior to version 2.63.16 contains a vulnerability that fails to properly restrict the scope and permissions when self-signup is enabled with the default CreateUserDir setting. This security flaw allows unauthenticated attackers to register accounts which inherit the server root scope, granting them full permissions to create, modify, delete, rename, share, and download files. Consequently, this results in unrestricted access to sensitive files and system resources, potentially compromising the integrity and confidentiality of the server's data.

Affected Version(s)

filebrowser 0 <= 2.63.16

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

je-lv
.