Path Traversal Vulnerability in File Browser by File Browser Team
CVE-2026-90930

7.6HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-90930?

The File Browser application, up to version 2.63.23, has a vulnerability related to its handling of symbolic links. While the application applies path rules to the requested lexical path, it fails to reapply these rules after resolving symbolic links. This flaw allows authenticated users to bypass security measures intended to restrict access to certain files. As a result, attackers can exploit this vulnerability to read and overwrite files that are meant to be protected, simply by accessing the files through symbolic link aliases that point to denied paths. This exposes sensitive data and modifies files without authorization, making it crucial for users of affected versions to implement mitigations and update to secure versions.

Affected Version(s)

filebrowser 0 <= 2.63.23

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SAYUTIM
.