CVE-2026-82236
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Schwachstellenklasse
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Quellen
- https://github.com/filebrowser/filebrowser/commit/0231b7eb
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-r6pg-pg54-rcr5
- https://www.vulncheck.com/advisories/file-browser-2.63.6-through-2.63.23-share-link-exposure-via-file-deletion
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-r6pg-pg54-rcr5
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.