Insufficiently protected credentials in FileBrowser - #VU136928

 

Insufficiently protected credentials in FileBrowser - #VU136928

Published: July 6, 2026


Vulnerability identifier: #VU136928
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and bypass password protection for shared resources.

The vulnerability exists due to insufficiently protected credentials in the share API when handling share creation and listing requests. A remote privileged user can retrieve the exposed password hash and bypass token from JSON responses to disclose sensitive information and bypass password protection for shared resources.

An administrator listing shares through GET /api/shares receives these secrets for every user's password-protected shares, and exposed bcrypt hashes may be subjected to offline cracking.


Affected software

FileBrowser

Remediation

Install security update from vendor's website.

FileBrowser - update to 2.63.17

External References

Related Security Bulletins