CVE-2026-82236: File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a surviving public share-link URL for a file that was deleted by a privileged user. No authentication is required to use that link after unrelated content is uploaded to the same path.
What conditions are required for exposure?
The issue requires a privileged user to delete another user's shared file, with the associated public share link not being cleaned up. New unrelated content must then be uploaded at the same path for the old link to expose it.
How can I determine whether content may already be exposed?
Review public share links associated with files deleted by privileged users and identify paths where new content was later uploaded. Those surviving links may permit unauthenticated retrieval of the replacement content.