PT-2026-72003 · Unknown · Filebrowser

·

CVE-2026-72834

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions filebrowser versions prior to 2.63.19
Description A permission bypass exists in the '/api/resources' endpoint. The resourceGetHandler function fails to perform a Perm.Download check when processing the checksum parameter. This allows an authenticated user who is restricted from downloading files to obtain a content-hash oracle (supporting md5, sha1, sha256, and sha512) for any file within their scope. This flaw can be used to confirm guessed content, detect changes to files, or perform offline brute-force attacks on files with low entropy.
Recommendations Update to version 2.63.19 or later. As a temporary mitigation, restrict access to the '/api/resources' endpoint for users who should not have download permissions.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72834
GHSA-7WHW-Q6GH-XR59

Affected Products

Filebrowser