PT-2026-71439 · Unknown · Filebrowser
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
File Browser versions 2.50.0 through 2.63.21
Description
An issue exists where the software fails to validate the expiration of JSON Web Tokens (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—when proxy authentication is configured using a non-default logout page. This allows attackers possessing a previously valid token to maintain indefinite access to protected routes and administrative endpoints. Additionally, expired tokens can be exchanged for new ones through the renewal endpoint.
Recommendations
Update File Browser to a version later than 2.63.21.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filebrowser