Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-72834— filebrowser before 2.63.19 Permission Bypass via checksum

Quick assessment

Affected
filebrowser filebrowser
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.63.19之前版本存在信息泄露漏洞,该漏洞源于/api/resources端点未执行Perm.Download检查,可能导致已认证用户获取文件内容哈希,进而确认文件内容、检测文件变化及对低熵文件进行离线暴力破解。

CVSS 4.3 · Medium EPSS 0.39% · P31

Affected Version Matrix 2

VendorProduct Version RangeStatus
filebrowser filebrowser < 2.63.19 affected
2.63.19 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72834

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
filebrowser before 2.63.19 Permission Bypass via checksum
Source: CVE Program / CVE List V5
Vulnerability Description
filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and subtitle paths). As a result, an authenticated user provisioned with Perm.Download=false can obtain a content-hash oracle for any same-scope file (md5/sha1/sha256/sha512), enabling confirmation of known/guessed content, change detection, and offline brute-force of low-entropy files. This is an incomplete fix of CVE-2026-35606; it bypasses only the Download permission and does not defeat scope/path authorization.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
File Browser 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.63.19之前版本存在信息泄露漏洞,该漏洞源于/api/resources端点未执行Perm.Download检查,可能导致已认证用户获取文件内容哈希,进而确认文件内容、检测文件变化及对低熵文件进行离线暴力破解。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
filebrowser filebrowser 0 ~ 2.63.19 -

II. Public POCs for CVE-2026-72834

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72834

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-72834 (1)

Vendor Advisories for CVE-2026-72834 (2)

Same Patch Batch · filebrowser · 2026-08-14 · 5 CVEs total

CVE-2026-72837 8.8 HIGH File Browser before 2.63.20 Privilege Escalation via Proxy Authentication
CVE-2026-72836 8.1 HIGH FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
CVE-2026-72835 6.8 MEDIUM filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
CVE-2026-72838 6.5 MEDIUM FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload

IV. Related Vulnerabilities

V. Comments for CVE-2026-72834

No comments yet


Leave a comment