Incorrect authorization in FileBrowser - #VU139761
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to access and modify files belonging to other users and data under the server root.
The vulnerability exists due to incorrect authorization in proxy and hook authentication auto-provisioning when creating user directories with createUserDir enabled and the default scope set to .. A remote user can authenticate with a valid upstream identity to obtain the server root as scope to access and modify files belonging to other users and data under the server root.
This affects proxy authentication and hook authentication for previously unknown users when hook authentication does not return an explicit user.scope.