CVE-2026-73611: File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
File Browserto a version that resolves this vulnerability.Fixed in 2.63.21 - Upgrade
Upgrade
File Browserto a version that resolves this vulnerability.Fixed in 2.50.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73611?
The severity of CVE-2026-73611 is rated as medium with a score of 6.8.
How do I fix CVE-2026-73611?
To fix CVE-2026-73611, upgrade File Browser to version 2.63.22 or later which addresses the JWT expiration bypass issue.
What vulnerability does CVE-2026-73611 exploit?
CVE-2026-73611 exploits the failure to validate JWT expiration in File Browser when proxy authentication uses a non-default logout page.
What are the potential consequences of CVE-2026-73611?
The consequences of CVE-2026-73611 include unauthorized access to protected routes and administrative endpoints due to indefinite token validity.
Who is affected by CVE-2026-73611?
CVE-2026-73611 affects users of File Browser versions 2.50.0 through 2.63.21 that utilize a non-default logout page for proxy authentication.