PT-2026-52537 · Unknown · Filebrowser
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
File Browser versions 2.0.0-rc.1 and later
Description
When configured with proxy authentication (
auth.method=proxy), the software improperly trusts upstream identity headers without validating that requests originate from a trusted proxy. An unauthenticated attacker with direct access to the server can impersonate any user, including the administrator, by sending a forged HTTP header. Furthermore, providing a non-existent username in the header triggers the automatic creation of a new user account, allowing unauthorized account provisioning. This leads to full administrative account takeover and complete compromise of server-side file management.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict direct access to the File Browser server to ensure requests only reach the application through a trusted proxy.
Avoid using the
auth.method=proxy configuration if a trusted proxy cannot be strictly enforced.Exploit
Improper Authentication
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filebrowser