Junglewise Threat Intelligence

CVE-2026-54685: gtsteffaniak FileBrowser Quantum username enumeration via timing side-channel

CVE-2026-54685 · Severity: medium · CVSS 5.3 · Published 2026-07-20

Technologies: github.com/gtsteffaniak/filebrowser/backend (Go), Gtsteffaniak FileBrowser Quantum. Vendors: Go, Gtsteffaniak.

Executive brief

FileBrowser Quantum is a self-hosted web application used for managing files remotely. A security flaw in its login system allows unauthorized individuals to determine which usernames exist on the server by measuring how long the system takes to respond to login attempts. This information can be used to launch more targeted attacks, such as password guessing or social engineering, against known valid accounts.

Technical details

The `/api/auth/login` authentication endpoint in FileBrowser Quantum prior to version 1.3.2-beta does not execute in constant time, leading to a CWE-208 observable timing discrepancy. The root cause is located in the `Auth` function of `JSONAuth` within `auth/json.go`, which returns an error immediately if a username is not found in the database but proceeds to a computationally expensive bcrypt password comparison if the username is valid. An unauthenticated remote attacker can measure these millisecond-level differences (e.g., ~1-4ms for invalid users vs. ~40-50ms for valid users) to enumerate valid accounts. The vulnerability is remediated in version 1.3.2-beta by ensuring the authentication logic maintains consistent execution time regardless of username validity.

Affected products

  • gtsteffaniak FileBrowser Quantum < 1.3.2-beta

Timeline

  • 2026-03-21: patched: Version 1.3.2-beta released with fix
  • 2026-07-20: disclosed: Public advisory and CVE published

References

Related threats