CVE-2026-30933
FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.
| CWE | CWE-200 CWE-306 CWE-602 |
| Vendor | gtsteffaniak |
| Product | filebrowser |
| Published | Mar 10, 2026 |
| Last Updated | Mar 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for gtsteffaniak filebrowser
Be the first to know when new high vulnerabilities affecting gtsteffaniak filebrowser are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
gtsteffaniak / filebrowser
>= 1.3.0-beta, < 1.3.1-beta >= 1.2.6-beta, < 1.2.2-stable = 1.1.3-stable