CVE-2026-72837
Received Received - Intake

File Browser Authentication Bypass via Server Root Scope

Vulnerability report for CVE-2026-72837, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: VulnCheck

Description

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
filebrowser file_browser to 2.63.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

File Browser versions before 2.63.20 fail to enforce user directory isolation during proxy and hook authentication. This allows attackers with valid upstream credentials to access, modify, delete, or share files belonging to other users by exploiting improper scope assignment.

Detection Guidance

Check File Browser version with: filebrowser version. If version is below 2.63.20, the system is vulnerable. Inspect proxy and hook authentication logs for unauthorized root scope assignments or user directory access attempts.

Impact Analysis

If you use File Browser versions before 2.63.20 with proxy or hook authentication, an attacker could read, modify, or delete your files or others' files, bypassing intended user isolation. This could lead to data breaches, unauthorized file changes, or complete system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade File Browser to version 2.63.20 or later immediately. Disable createUserDir isolation if using proxy or hook authentication. Review and restrict user scopes to prevent root-level access. Monitor for unauthorized file access or modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72837. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart