Improper Handling of Case Sensitivity in FileBrowser - #VU139757

 

Improper Handling of Case Sensitivity in FileBrowser - #VU139757

Published: July 27, 2026


Vulnerability identifier: #VU139757
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-178
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read, overwrite, and delete another user's files.

The vulnerability exists due to improper handling of case sensitivity in the signup username and home directory scope ownership check when creating self-registered accounts on a case-insensitive filesystem. A remote attacker can register a second account whose username differs only by letter case to read, overwrite, and delete another user's files.

Exploitation requires signup and automatic user directory creation to be enabled, with the application root located on a case-insensitive Windows filesystem.


Affected software

FileBrowser

Remediation

Install security update from vendor's website.

FileBrowser - update to 2.63.19

External References

Related Security Bulletins