File Browser File Browser是File Browser团队的一款文件浏览管理软件。 File Browser 2.63.6之前版本存在授权问题漏洞,该漏洞源于低权限用户通过合法DELETE操作可破坏其他用户的分享链接记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filebrowser | filebrowser | < 2.63.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | < 2.63.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54089 | 9.1 CRITICAL | File Browser: Authentication Bypass via Proxy Auth Header Forgery |
| CVE-2026-54096 | 8.4 HIGH | File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existe |
| CVE-2026-55667 | 8.2 HIGH | File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-followin |
| CVE-2026-54094 | 7.5 HIGH | File Browser: Symlink following lets scoped users read, overwrite, and share files outside |
| CVE-2026-54091 | 7.5 HIGH | File Browser: Incorrect access control in public directory shares via rule path rebasing |
| CVE-2026-54092 | 6.5 MEDIUM | File Browser: DoS Vulnerability on Public Login API |
| CVE-2026-54090 | File Browser: Command Allowlist Bypass via Shell Metacharacter Injection | |
| CVE-2026-54088 | File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentica | |
| CVE-2026-54093 | File Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators |
No comments yet