Incorrect authorization in FileBrowser - CVE-2026-54091
Published: June 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in public share handlers when processing requests for files and subdirectories beneath a shared directory using rebased relative paths. A remote attacker can request a specially crafted public share path to disclose sensitive information.
No authenticated session is required if the public share is not password protected.