Vulnerability Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/gtsteffaniak/filebrowser/commit/af08800667b874620edc6f44c3e2e
- https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.2-beta
- https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f
- https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f
FAQ
What is CVE-2026-54685?
CVE-2026-54685 is a vulnerability with a CVSS score of 5.3 (MEDIUM). FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent us...
How severe is CVE-2026-54685?
CVE-2026-54685 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54685?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.