Out-of-Scope File Deletion Vulnerability in Filebrowser by Filebrowser
CVE-2026-73613

7.2HIGH

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73613?

Filebrowser versions prior to 2.63.19 are vulnerable to an out-of-scope file deletion due to flaws in the TUS upload cache eviction mechanism. This vulnerability enables authenticated users, having only Create permissions, to delete arbitrary files that fall outside their authorized scope. By exploiting this flaw, an attacker can create a symlink that swaps an ancestor directory during the cache's time-to-live (TTL) window, thereby bypassing the ScopedFs scope guards and the necessary Perm.Delete checks. This results in the potential compromise of sensitive files, posing significant security risks.

Affected Version(s)

filebrowser 0 < 2.63.19

filebrowser 2.63.19

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
hacdias
.