PT-2026-49069 · Unknown · Filebrowser

·

CVE-2026-54097

·

Published

2026-06-12

·

Updated

2026-07-30

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions File Browser versions prior to 2.63.6
Description A low-privileged authenticated user with create and delete permissions in their own isolated scope can delete share-link records belonging to any other user, including the administrator. This occurs when the user performs a DELETE operation on a file in their own directory whose logical path is a byte-prefix of another user's stored share.Link.Path. The issue resides in the resourceDeleteHandler function within http/resource.go, which calls DeleteWithPathPrefix() without verifying the ownership of the share records being deleted. While the contents of the victim's files are not exposed, the share links are irrevocably wiped, potentially leading to a denial-of-service of the share-link feature.
Recommendations Update to version 2.63.6.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54097
GHSA-5WW9-JG6Q-38R7
GO-2026-5159
OPENSUSE-SU-2026:21483-1

Affected Products

Filebrowser