Incorrect authorization in FileBrowser - #VU139761

 

Incorrect authorization in FileBrowser - #VU139761

Published: July 27, 2026


Vulnerability identifier: #VU139761
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access and modify files belonging to other users and data under the server root.

The vulnerability exists due to incorrect authorization in proxy and hook authentication auto-provisioning when creating user directories with createUserDir enabled and the default scope set to .. A remote user can authenticate with a valid upstream identity to obtain the server root as scope to access and modify files belonging to other users and data under the server root.

This affects proxy authentication and hook authentication for previously unknown users when hook authentication does not return an explicit user.scope.


Affected software

FileBrowser

Remediation

Install security update from vendor's website.

FileBrowser - update to 2.63.20

External References

Related Security Bulletins