CVE Explorer
CVE-2026-25889
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a case-sensitivity flaw in the password validation logic allows any authenticated user to change their password (or an admin to change any user's password) without providing the current password. By using Title Case field name "Password" instead of lowercase "password" in the API request, the current_password verification is completel
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"filebrowser","vendor":"filebrowser","versions":[{"status":"affected","version":"< 2.57.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c03f120442ecba5c8019778e270c4c94fe3b57f9e1b5061e24e3dd97d5e3c38b · sha256:256ac5a67249d266… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c03f120442ecba5c8019778e270c4c94fe3b57f9e1b5061e24e3dd97d5e3c38b · sha256:256ac5a67249d266… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-178","description":"CWE-178: Improper Handling of Case Sensitivity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c03f120442ecba5c8019778e270c4c94fe3b57f9e1b5061e24e3dd97d5e3c38b · sha256:256ac5a67249d266… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/filebrowser/filebrowser/commit/ff2f00498cff151e2fb1f5f0b16963bf33c3d6d4","tags":["x_refsource_MISC"],"url":"https://github.com/filebrowser/filebrowser/commit/ff2f00498cff151e2fb1f5f0b16963bf33c3d6d4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c03f120442ecba5c8019778e270c4c94fe3b57f9e1b5061e24e3dd97d5e3c38b · sha256:256ac5a67249d266… · /containers/cna/references/1
{"name":"https://github.com/filebrowser/filebrowser/releases/tag/v2.57.1","tags":["x_refsource_MISC"],"url":"https://github.com/filebrowser/filebrowser/releases/tag/v2.57.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c03f120442ecba5c8019778e270c4c94fe3b57f9e1b5061e24e3dd97d5e3c38b · sha256:256ac5a67249d266… · /containers/cna/references/2
{"name":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-hxw8-4h9j-hq2r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-hxw8-4h9j-hq2r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c03f120442ecba5c8019778e270c4c94fe3b57f9e1b5061e24e3dd97d5e3c38b · sha256:256ac5a67249d266… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.