Authorization Bypass in File Browser by FileBrowser
CVE-2026-73612
8.6HIGH
What is CVE-2026-73612?
File Browser prior to version 2.63.22 has a critical flaw where it does not properly enforce access rules for child elements during recursive operations like copy, rename, and delete. This loophole permits authenticated users to manipulate files which they are normally restricted from accessing by merely targeting a permitted parent directory. As a result, attackers can undermine the application's rule-based isolation mechanisms, compromising both the confidentiality and integrity of sensitive files.
Affected Version(s)
filebrowser 0 < 2.63.22
filebrowser 2.63.22
