Junglewise Threat Intelligence

CVE-2026-54091: File Browser incorrect authorization in public directory shares

CVE-2026-54091 · Severity: high · CVSS 7.5 · Published 2026-06-25

Technologies: File Browser, github.com/filebrowser/filebrowser (Go), github.com/filebrowser/filebrowser/v2 (Go). Vendors: FileBrowser, File Browser, Go.

Executive brief

File Browser, a web-based file management interface, contains a security flaw in how it handles public file sharing. An attacker who obtains a public share link can bypass security rules set by the owner to access restricted files or folders located within the shared directory. This could lead to the unauthorized disclosure of sensitive data, such as private documents or configuration files, without requiring a password or account.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in File Browser's public share handlers. When a directory is shared publicly, the application rebases the filesystem root to that directory but evaluates access rules using the new relative path instead of the original absolute path. Because the owner's 'deny' rules are typically defined relative to the original root, they fail to match the rebased paths (e.g., a rule blocking '/projects/private' will not match a request for '/private' within a share rooted at '/projects'). An unauthenticated attacker with a valid share URL can exploit this via the `/api/public/share/*` and `/api/public/dl/*` endpoints to read files or list directories that should be restricted. This issue is resolved in version 2.63.6.

Affected products

  • filebrowser File Browser < 2.63.6

Timeline

  • 2026-06-03: patched: Version 2.63.6 released
  • 2026-06-06: advisory: GitHub Security Advisory published
  • 2026-06-25: disclosed: CVE published to NVD

References

Related threats