CVE-2026-72837

8.8

filebrowser · filebrowser

File Browser contains an improper access control vulnerability that enables authenticated users to escalate privileges via proxy authentication.

Executive summary

An improper access control vulnerability in File Browser allows authenticated attackers to escalate their privileges, posing a critical risk to file system security.

Vulnerability

The application fails to properly enforce access controls (CWE-284) during proxy authentication processes. This allows an authenticated user to perform actions outside their assigned permission scope.

Business impact

This vulnerability carries a CVSS score of 8.8, reflecting the high potential for total system impact. Unauthorized privilege escalation could result in full access to the underlying file system, leading to data exfiltration, modification, or destruction of sensitive information.

Remediation

Immediate Action: Update the File Browser installation to version 2.63.20 or later immediately to resolve the access control flaw.

Proactive Monitoring: Monitor system logs for unexpected privilege escalation events or access requests to directories outside of the expected user scope.

Compensating Controls: Restrict network access to the File Browser interface to trusted internal segments only, and ensure that authentication providers are configured with the principle of least privilege.

Exploitation status

Public Exploit Available: No confirmed public exploit (exploit_available: false).

Analyst recommendation

Due to the availability of a proof-of-concept and the high severity of potential privilege escalation, organizations must treat this update with high urgency. Patching to the current version is the only effective way to neutralize the risk of unauthorized file system access.

More filebrowser CVEs