Vulnerability Description
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/filebrowser/filebrowser/commit/72faf6dd3c85628e332d3e567124b8
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-77x8-73f4-54
- https://www.vulncheck.com/advisories/file-browser-before-authorization-bypass-vi
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-77x8-73f4-54
FAQ
What is CVE-2026-73612?
CVE-2026-73612 is a vulnerability with a CVSS score of 8.1 (HIGH). File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Att...
How severe is CVE-2026-73612?
CVE-2026-73612 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73612?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.