SB20260727346 - Incorrect authorization in FileBrowser
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access and modify files belonging to other users and data under the server root.
The vulnerability exists due to incorrect authorization in proxy and hook authentication auto-provisioning when creating user directories with createUserDir enabled and the default scope set to .. A remote user can authenticate with a valid upstream identity to obtain the server root as scope to access and modify files belonging to other users and data under the server root.
This affects proxy authentication and hook authentication for previously unknown users when hook authentication does not return an explicit user.scope.
Remediation
Install update from vendor's website.