CVE Explorer
CVE-2026-35607
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users created via the signup handler. The same fix was not applied to the proxy auth handler. Users auto-created on first successful proxy-auth login are granted execution capabilities from global defaults, even though the s
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"filebrowser","vendor":"filebrowser","versions":[{"status":"affected","version":"< 2.63.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7aab65b6c0f4ad8c112eb9c9fedd31ea5612018f9ebc9d2e4d53fd752200c494 · sha256:ff4b3d0c0735f806… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7aab65b6c0f4ad8c112eb9c9fedd31ea5612018f9ebc9d2e4d53fd752200c494 · sha256:ff4b3d0c0735f806… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7aab65b6c0f4ad8c112eb9c9fedd31ea5612018f9ebc9d2e4d53fd752200c494 · sha256:ff4b3d0c0735f806… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/filebrowser/filebrowser/pull/5890","tags":["x_refsource_MISC"],"url":"https://github.com/filebrowser/filebrowser/pull/5890"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7aab65b6c0f4ad8c112eb9c9fedd31ea5612018f9ebc9d2e4d53fd752200c494 · sha256:ff4b3d0c0735f806… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7526-j432-6ppp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7aab65b6c0f4ad8c112eb9c9fedd31ea5612018f9ebc9d2e4d53fd752200c494 · sha256:ff4b3d0c0735f806… · /containers/adp/0/references/0
{"name":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7526-j432-6ppp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7526-j432-6ppp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7aab65b6c0f4ad8c112eb9c9fedd31ea5612018f9ebc9d2e4d53fd752200c494 · sha256:ff4b3d0c0735f806… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.