CVE-2026-73611
Received Received - Intake

JWT Expiration Bypass in File Browser via Proxy Auth

Vulnerability report for CVE-2026-73611, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: VulnCheck

Description

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
file_browser file_browser From 2.50.0 (inc) to 2.63.21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

File Browser versions 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication uses a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely. Expired tokens can also be exchanged for fresh ones via the renewal endpoint.

Detection Guidance

Check File Browser version with: filebrowser version. If between 2.50.0 and 2.63.21, it is vulnerable. Inspect logs for unauthorized access attempts or token renewal requests to /api/renew. Monitor for persistent sessions despite token expiration.

Impact Analysis

Attackers can gain unauthorized access to sensitive data and administrative functions. They can maintain access indefinitely by renewing expired tokens, bypassing intended session expiration controls. This risks data theft, unauthorized modifications, and potential system compromise.

Compliance Impact

This vulnerability likely violates compliance requirements for session management and data protection. GDPR and HIPAA mandate proper session expiration and access controls. Unauthorized access risks data breaches, which could lead to regulatory penalties and loss of trust.

Mitigation Strategies

Upgrade File Browser to version 2.63.22 or later. If upgrading is not possible, revert to the default logout page setting to disable the token expiration waiver. Review and revoke all active sessions and tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73611. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart