PT-2026-71439 · Unknown · Filebrowser

·

CVE-2026-73611

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions File Browser versions 2.50.0 through 2.63.21
Description An issue exists where the software fails to validate the expiration of JSON Web Tokens (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—when proxy authentication is configured using a non-default logout page. This allows attackers possessing a previously valid token to maintain indefinite access to protected routes and administrative endpoints. Additionally, expired tokens can be exchanged for new ones through the renewal endpoint.
Recommendations Update File Browser to a version later than 2.63.21.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73611
GHSA-V3JV-RMH2-635J

Affected Products

Filebrowser