PT-2026-52537 · Unknown · Filebrowser

·

CVE-2026-54089

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions File Browser versions 2.0.0-rc.1 and later
Description When configured with proxy authentication (auth.method=proxy), the software improperly trusts upstream identity headers without validating that requests originate from a trusted proxy. An unauthenticated attacker with direct access to the server can impersonate any user, including the administrator, by sending a forged HTTP header. Furthermore, providing a non-existent username in the header triggers the automatic creation of a new user account, allowing unauthorized account provisioning. This leads to full administrative account takeover and complete compromise of server-side file management.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict direct access to the File Browser server to ensure requests only reach the application through a trusted proxy. Avoid using the auth.method=proxy configuration if a trusted proxy cannot be strictly enforced.

Exploit

Improper Authentication

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54089
GHSA-XQP3-JQ6G-X3QM
GO-2026-5966
OPENSUSE-SU-2026:21483-1

Affected Products

Filebrowser