Incorrect Privilege Assignment in FileBrowser - #VU139755

 

Incorrect Privilege Assignment in FileBrowser - #VU139755

Published: July 27, 2026


Vulnerability identifier: #VU139755
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read, modify, and delete arbitrary files managed by the application.

The vulnerability exists due to incorrect privilege assignment in the signupHandler endpoint when creating accounts through self-registration. A remote attacker can register a new account and inherit the server root scope with create, modify, delete, rename, share, and download permissions to read, modify, and delete arbitrary files managed by the application.

Exploitation requires self-registration to be enabled while the default CreateUserDir setting remains unchanged.


Affected software

FileBrowser

Remediation

Install security update from vendor's website.

FileBrowser - update to 2.63.17

External References

Related Security Bulletins