Improper Handling of Case Sensitivity in FileBrowser - #VU139757
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to read, overwrite, and delete another user's files.
The vulnerability exists due to improper handling of case sensitivity in the signup username and home directory scope ownership check when creating self-registered accounts on a case-insensitive filesystem. A remote attacker can register a second account whose username differs only by letter case to read, overwrite, and delete another user's files.
Exploitation requires signup and automatic user directory creation to be enabled, with the application root located on a case-insensitive Windows filesystem.