PT-2026-52539 · Unknown · Filebrowser

·

CVE-2026-55667

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions File Browser versions prior to 2.63.16
Description A scoped, non-admin user with only Create permissions can delete arbitrary files outside their assigned scope, including other tenants' data and the application database. This occurs during the upload failure-cleanup process in the direct-upload handler. The issue stems from the ScopedFs.RemoveAll() function, which fails to enforce the symlink guard used by other methods. If a directory symlink that escapes the scope already exists within the user's directory, an authenticated user can trigger a failed upload to execute ScopedFs.RemoveAll() on a user-controlled path, bypassing both the ScopedFs boundary and the delete permission requirement.
Recommendations Update File Browser to version 2.63.16.

Exploit

Fix

DoS

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55667
GHSA-FMM7-X4GX-8JHR
GO-2026-6021
OPENSUSE-SU-2026:21483-1

Affected Products

Filebrowser