Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-73611— File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass

Quick assessment

Affected
filebrowser filebrowser
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.50.0版本至2.63.21版本存在会话机制问题漏洞,该漏洞源于在代理认证配置了非默认登出页面时未验证JWT过期时间,可能导致攻击者利用先前有效的令牌无限期访问受保护路由和管理端点,并通过续订端点将过期令牌兑换为新令牌。

CVSS 6.8 · Medium EPSS 0.43% · P35

Affected Version Matrix 1

VendorProduct Version RangeStatus
filebrowser filebrowser 2.50.0≤ 2.63.21 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73611

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5
Vulnerability Title
File Browser 会话机制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.50.0版本至2.63.21版本存在会话机制问题漏洞,该漏洞源于在代理认证配置了非默认登出页面时未验证JWT过期时间,可能导致攻击者利用先前有效的令牌无限期访问受保护路由和管理端点,并通过续订端点将过期令牌兑换为新令牌。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
filebrowser filebrowser 2.50.0 ~ 2.63.21 -

II. Public POCs for CVE-2026-73611

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73611

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-73611 (1)

Vendor Advisories for CVE-2026-73611 (2)

Same Patch Batch · filebrowser · 2026-08-13 · 4 CVEs total

CVE-2026-72839 9.8 CRITICAL filebrowser through 2.63.16 Privilege Escalation via Signup
CVE-2026-73613 8.2 HIGH filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink
CVE-2026-73612 8.1 HIGH File Browser before v2.63.22 Authorization Bypass via Recursive Operations

IV. Related Vulnerabilities

V. Comments for CVE-2026-73611

No comments yet


Leave a comment