Executive brief
File Browser is a web-based file management interface used to upload, edit, and share files. A security flaw allows a standard user to accidentally or intentionally delete the "share links" created by other users, including administrators. While the actual files remain safe, the links used to share those files with others are permanently destroyed, causing a disruption in operations and data sharing workflows.
Technical details
An authorization bypass exists in the 'DeleteWithPathPrefix' function within the Bolt storage backend. When a user deletes a file, the 'resourceDeleteHandler' attempts to clean up associated share links by matching the logical path prefix. Because this cleanup process does not verify the 'UserID' associated with the share links, a malicious user can delete a file with a short name (e.g., a single character) to trigger a prefix match that wipes share links belonging to other users, including administrators. This occurs because the application uses the logical path from the request rather than an absolute or user-scoped path. The vulnerability is fixed in version 2.63.6.
Affected products
- filebrowser filebrowser < 2.63.6
Timeline
- 2026-06-03: patched: Version 2.63.6 released
- 2026-06-25: disclosed: CVE-2026-54097 published