Vulnerability Description
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-j7jh-37pf-mf
- https://www.vulncheck.com/advisories/file-browser-before-privilege-escalation-vi
FAQ
What is CVE-2026-72837?
CVE-2026-72837 is a vulnerability with a CVSS score of 8.8 (HIGH). File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can rea...
How severe is CVE-2026-72837?
CVE-2026-72837 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72837?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.