PT-2026-72007 · Unknown · Filebrowser

·

CVE-2026-72838

·

Published

2026-08-14

·

Updated

2026-08-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FileBrowser versions prior to 2.63.19
Description Authenticated users can write arbitrary data to disk because the software fails to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint. This allows attackers to send oversized request bodies that exceed the declared upload length, potentially exhausting available disk space and causing service unavailability.
Recommendations Update to version 2.63.19 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72838
GHSA-FFV3-7H97-993Q

Affected Products

Filebrowser