JWT Expiration Bypass in File Browser by File Browser
CVE-2026-73611

7.6HIGH

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73611?

Versions 2.50.0 through 2.63.21 of File Browser are susceptible to a critical flaw where the expiration of JWT tokens is not validated when proxy authentication is set up with a non-default logout page. This vulnerability allows attackers to maintain access to secured routes and administrative functions by exploiting previously valid tokens, even if they have expired. They can circumvent token expiration by utilizing the renewal endpoint to generate new tokens, effectively granting them prolonged access to sensitive areas of the application. I.T. administrators must take caution and apply the recommended patches to mitigate this risk.

Affected Version(s)

filebrowser 0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hacdias
.