CVE-2026-72837: File Browser before 2.63.20 Privilege Escalation via Proxy Authentication
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
File Browserto a version that resolves this vulnerability.Fixed in 2.63.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72837?
The severity of CVE-2026-72837 is rated high with a score of 8.8.
How do I fix CVE-2026-72837?
To fix CVE-2026-72837, upgrade to File Browser version 2.63.20 or later.
What are the risks associated with CVE-2026-72837?
The risks include unauthorized access allowing attackers to read, modify, delete, and share files belonging to other users.
Who is affected by CVE-2026-72837?
Users of File Browser versions before 2.63.20 are affected by CVE-2026-72837.
What vulnerability does CVE-2026-72837 address?
CVE-2026-72837 addresses a privilege escalation vulnerability via proxy authentication in File Browser.