Vulnerability Description
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only in letter case (e.g., CaseVictim and casevictim) are stored as distinct accounts but resolve to the same physical home directory, because the scope-ownership check compares the persisted scope as an exact case-sensitive string. A second registrant can therefore read, overwrite, and delete another account's files through authenticated HTTP endpoints, without needing an existing account or victim interaction.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/filebrowser/filebrowser/commit/fe7efb2e6afe66774cd86a5b0a0303
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-576v-w77m-gr
- https://www.vulncheck.com/advisories/filebrowser-before-case-sensitivity-authent
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-576v-w77m-gr
FAQ
What is CVE-2026-72836?
CVE-2026-72836 is a vulnerability with a CVSS score of 8.1 (HIGH). FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser'...
How severe is CVE-2026-72836?
CVE-2026-72836 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72836?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.