PT-2026-71902 · Unknown · Filebrowser
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
filebrowser versions prior to 2.63.17
Description
An issue exists when self-signup is enabled using the default
CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope, granting them full permissions to create, modify, delete, rename, share, and download all files on the server.Recommendations
Update to a version newer than 2.63.16.
Disable the self-signup feature or modify the
CreateUserDir setting to restrict user scope.Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filebrowser