#VU125395 Incorrect authorization in FileBrowser - CVE-2026-32761
Published: April 8, 2026
FileBrowser
File Browser
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in the public share download flow when handling public share download requests for files shared by a user without download privileges. A remote user can create a public share link and retrieve the shared file content to disclose sensitive information.
Exploitation requires an authenticated user account with share permission enabled while download permission is denied, and the exposed content can then be accessed through an unauthenticated public share URL.