SB20260727346 - Incorrect authorization in FileBrowser



SB20260727346 - Incorrect authorization in FileBrowser

Published: July 27, 2026

Security Bulletin ID SB20260727346
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access and modify files belonging to other users and data under the server root.

The vulnerability exists due to incorrect authorization in proxy and hook authentication auto-provisioning when creating user directories with createUserDir enabled and the default scope set to .. A remote user can authenticate with a valid upstream identity to obtain the server root as scope to access and modify files belonging to other users and data under the server root.

This affects proxy authentication and hook authentication for previously unknown users when hook authentication does not return an explicit user.scope.


Remediation

Install update from vendor's website.