PT-2026-7167 · Unknown · Filebrowser

Dogadmin

·

Published

2026-02-09

·

Updated

2026-03-03

·

CVE-2026-25889

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions File Browser versions prior to 2.57.1
Description File Browser offers a file management interface for tasks like uploading, deleting, previewing, renaming, and editing files. A flaw in the password validation process, specifically a case-sensitivity issue, allows authenticated users to modify their passwords—or, for administrators, any user's password—without providing the current password. This bypass occurs when the 'Password' field is capitalized in the API request instead of using lowercase 'password', effectively circumventing the current password verification. Successful exploitation, potentially through methods like cross-site scripting (XSS) or session hijacking to obtain a valid JSON Web Token (JWT), can lead to account takeover. The vulnerable parameter is password. The affected API endpoint is not explicitly mentioned.
Recommendations Update to version 2.57.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-25889
GHSA-HXW8-4H9J-HQ2R
GO-2026-4475
SUSE-SU-2026:0757-1

Affected Products

Filebrowser