CVE-2026-73612: File Browser before v2.63.22 Authorization Bypass via Recursive Operations
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73612?
CVE-2026-73612 has a high severity rating of 8.1.
How do I fix CVE-2026-73612?
To fix CVE-2026-73612, upgrade File Browser to version 2.63.22 or later.
What kind of attack does CVE-2026-73612 enable?
CVE-2026-73612 enables authenticated users to bypass path-based access controls to copy, rename, or delete protected files.
Which versions of File Browser are affected by CVE-2026-73612?
File Browser versions before v2.63.22 are affected by CVE-2026-73612.
What operations are vulnerable in CVE-2026-73612?
CVE-2026-73612 is vulnerable during recursive copy, rename, and delete operations.