Use of Incorrectly-Resolved Name or Reference in FileBrowser - CVE-2026-62685
Published: July 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to read and modify another user's files.
The vulnerability exists due to use of incorrectly-resolved name or reference in home directory scope generation when registering a username that normalizes to an existing user's scope. A remote attacker can register a specially crafted username to read and modify another user's files.
Exploitation requires both self-registration and automatic home-directory creation to be enabled.