PT-2026-7168 · Unknown · Filebrowser

Fluxmux

·

Published

2026-02-09

·

Updated

2026-03-03

·

CVE-2026-25890

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions File Browser versions prior to 2.57.1
Description File Browser offers a file management interface for tasks like uploading, deleting, previewing, renaming, and editing files within a designated directory. Before version 2.57.1, an authenticated user could circumvent the application's file path restrictions by manipulating the request URL. Specifically, adding multiple slashes (e.g., //private/) to the path causes the authorization check to fail, while the filesystem correctly resolves the path, potentially granting unauthorized access to restricted files. The vulnerability involves bypassing the application’s “Disallow” file path rules.
Recommendations Update to File Browser version 2.57.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25890
GHSA-4MH3-H929-W968
GO-2026-4474
SUSE-SU-2026:0757-1

Affected Products

Filebrowser