Executive brief
filebrowser is a lightweight file manager used to serve and manage files over a web interface. When self-signup is enabled with default settings, unauthenticated users can register accounts that automatically gain access to the entire server's file system with full permissions to read, modify, delete, and share all files—including those belonging to other users and sensitive system data.
Technical details
The vulnerability exists in the signup handler (POST /api/signup) due to improper permission initialization when self-registration is enabled. The code applies default settings (which set Scope to "/" and include full CRUD permissions), then only strips Admin, Execute, and Commands privileges—leaving Create, Modify, Delete, Rename, Share, and Download permissions intact. Additionally, when the default CreateUserDir setting is false, the Scope reset logic is bypassed, and path normalization causes "." to be converted to "/" (server root). As a result, any unauthenticated attacker can register an account and immediately access all files the server manages. No authentication, special configuration, or user interaction is required beyond enabling signup.
Affected products
- filebrowser filebrowser through 2.63.16
Timeline
- 2026-07-25: disclosed: GitHub Security Advisory GHSA-6759-996p-gpj6 published
- 2026-08-13: advisory: CVE-2026-72839 published on NVD