Improper Resolution of Path Equivalence in FileBrowser - #VU139760
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to bypass administrator-defined access rules and disclose or modify files within their own scope.
The vulnerability exists due to improper resolution of path equivalence in the access rule checker when processing case-variant paths and Windows-separator paths. A remote user can request a specially crafted path to bypass administrator-defined access rules and disclose or modify files within their own scope.
This affects case-insensitive filesystems and Windows path handling, and does not grant access outside the user's assigned scope.