CVE-2026-35607
8.1File Browser · File Browser
File Browser versions prior to 2.63.1 contain an improper privilege management vulnerability where users created via proxy authentication are incorrectly granted excessive execution capabilities.
Executive summary
A privilege management flaw in File Browser allows newly created proxy-authenticated users to inherit unauthorized execution permissions, posing a significant risk of system compromise.
Vulnerability
The application fails to restrict execution permissions for users provisioned through the proxy authentication handler. While the standard signup handler was updated to block these rights, the proxy mechanism retains global defaults that grant elevated access to new accounts.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain unauthorized execution capabilities on the host system. Given the CVSS score of 8.1, this is a high-severity issue that could lead to full system compromise, unauthorized data modification, or service disruption within the managed directory.
Remediation
Immediate Action: Update the File Browser installation to version 2.63.1 or later to ensure proxy-authenticated users are restricted correctly.
Proactive Monitoring: Review user creation logs and audit account permissions for any users provisioned via proxy authentication to identify potential unauthorized execution rights.
Compensating Controls: If an immediate update is not feasible, consider disabling proxy authentication or restricting access to the File Browser interface to trusted internal networks only.
Exploitation status
Public Exploit Available: No (no confirmed public exploit exists in the provided data).
Analyst recommendation
This vulnerability presents a high risk due to the potential for unauthorized command execution by newly created accounts. Organizations currently utilizing proxy authentication with File Browser must prioritize the update to version 2.63.1 to close this privilege escalation vector and prevent unauthorized access to system resources.