CVE-2026-46410
Received Received - Intake

Information Disclosure in FileBrowser Quantum

Vulnerability report for CVE-2026-46410, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: GitHub, Inc.

Description

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
gtsteffaniak filebrowser to 1.3.2-stable (exc)
gtsteffaniak filebrowser to 1.4.1-beta (exc)
gtsteffaniak filebrowser 1.4.1
gtsteffaniak filebrowser to 1.3.1-stable (inc)
gtsteffaniak filebrowser to 1.4.0-beta (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-46410 is a vulnerability in FileBrowser Quantum, a self-hosted web-based file manager. It allows unauthenticated users to access sensitive information such as source code and file paths. The issue affects versions prior to 1.3.2-stable and 1.4.1-beta.

Detection Guidance

Check FileBrowser version with: filebrowser version. If running versions before 1.3.2-stable or 1.4.1-beta, the system is vulnerable. Inspect network traffic for unauthorized access to sensitive paths or source information.

Impact Analysis

This vulnerability could allow attackers to view confidential source code or file paths without authentication. This may lead to further exploitation, data breaches, or unauthorized access to sensitive information stored on the server.

Compliance Impact

Unauthorized access to sensitive data could result in violations of GDPR, HIPAA, or other regulations. This may lead to legal penalties, reputational damage, and loss of trust due to compromised data confidentiality.

Mitigation Strategies

Update FileBrowser to version 1.3.2-stable or 1.4.1-beta immediately. Restrict network access to the application until patched. Monitor logs for suspicious activity related to source or path access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46410. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart