#VU125395 Incorrect authorization in FileBrowser - CVE-2026-32761

 

#VU125395 Incorrect authorization in FileBrowser - CVE-2026-32761

Published: April 8, 2026


Vulnerability identifier: #VU125395
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-32761
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FileBrowser
Software vendor:
File Browser

Description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the public share download flow when handling public share download requests for files shared by a user without download privileges. A remote user can create a public share link and retrieve the shared file content to disclose sensitive information.

Exploitation requires an authenticated user account with share permission enabled while download permission is denied, and the exposed content can then be accessed through an unauthenticated public share URL.


Remediation

Install security update from vendor's website.

External links