CVE-2026-72839

9.8

filebrowser · filebrowser

Filebrowser through 2.63.16 contains an incorrect privilege assignment vulnerability that allows unauthenticated attackers to register accounts with full administrative access to the server root.

Executive summary

A critical vulnerability in filebrowser allows unauthenticated attackers to gain full administrative control over the file system by exploiting improper privilege assignment during account registration.

Vulnerability

This is an incorrect privilege assignment vulnerability (CWE-266) occurring when self-signup is enabled with default settings. The flaw permits unauthenticated attackers to create accounts that inherit the server root scope, granting them full read, write, and delete permissions across the entire file system.

Business impact

The potential for total system compromise is severe, as an attacker can exfiltrate sensitive data, modify core configurations, or delete critical files. Given the CVSS score of 9.8, this vulnerability represents an immediate threat to data integrity, confidentiality, and availability. Organizations relying on filebrowser for file management are at significant risk of total unauthorized access if this service is exposed to the internet.

Remediation

Immediate Action: Update filebrowser to the latest version immediately to ensure privilege restrictions are correctly enforced.

Proactive Monitoring: Review user registration logs for suspicious activity or unauthorized account creations that occurred recently.

Compensating Controls: Disable the self-signup feature and restrict network access to the filebrowser interface until the software has been successfully updated.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a catastrophic risk to any environment running an exposed instance of filebrowser. Administrators must prioritize updating the software to a patched version as the primary defense. Given the ease of exploitation, verify that all instances are secured and that unnecessary self-signup features are disabled immediately.

More filebrowser CVEs