PT-2026-72005 · Unknown · Filebrowser

·

CVE-2026-72836

·

Published

2026-08-14

·

Updated

2026-08-18

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FileBrowser versions prior to 2.63.19
Description An issue exists when the software is hosted on a case-insensitive filesystem, such as Windows/NTFS, and both Signup and CreateUserDir are enabled. The system fails to account for case-insensitivity during self-registration home directory ownership checks. Consequently, two users registering with names that differ only by case (e.g., CaseVictim and casevictim) are treated as distinct accounts but are mapped to the same physical home directory. This occurs because the scope-ownership check performs an exact case-sensitive string comparison. An attacker can register a similar username to read, overwrite, or delete files belonging to another account via authenticated HTTP endpoints without requiring victim interaction.
Recommendations Update to version 2.63.19 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72836
GHSA-576V-W77M-GR84

Affected Products

Filebrowser