Link following in FileBrowser - CVE-2026-54094

 

Link following in FileBrowser - CVE-2026-54094

Published: June 8, 2026


Vulnerability identifier: #VU133483
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54094
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and overwrite files outside the intended filebrowser scope.

The vulnerability exists due to improper link resolution before file access in the HTTP file handlers when processing paths that reference symbolic links inside a scoped directory. A remote attacker can access a symlink that points outside the scoped directory to disclose sensitive information and overwrite files outside the intended filebrowser scope.

If public sharing is permitted, the issue can also expose the outside target through a public share. The proof assumes a symlink already exists inside the user's scoped directory, or that another allowed workflow can place it there.


Affected software

FileBrowser

How to mitigate CVE-2026-54094

Install security update from vendor's website.

FileBrowser - update to 2.63.14

External References

Related Security Bulletins