๐Ÿ” CVE Alert

CVE-2026-72835

MEDIUM 6.8

filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope.

CWE CWE-41
Vendor filebrowser
Product filebrowser
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for filebrowser filebrowser

Be the first to know when new medium vulnerabilities affecting filebrowser filebrowser are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

filebrowser / filebrowser
0 < 2.63.21

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-fgm5-pw99-w2p7 vulncheck.com: https://www.vulncheck.com/advisories/filebrowser-before-access-rule-bypass-via-path-canonicalization

Credits

๐Ÿ” N1V6 hacdias