CVE-2026-82237: filebrowser through 2.63.23 Stale Share Link via File Rename

Published Aug 28, 2026
·
Updated

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared path — via re-upload, another user with create permission, or a hook — the stale public share link serves that new file under the original link's password and expiry settings, unexpectedly exposing it.

Affected Software

1 affected component
Filebrowser Filebrowser<=2.63.23

Event History

Aug 28, 2026
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to unintended file disclosure?

Instances that have public share links for files are exposed if a shared file is renamed and a new file is later created at the original path. The new file can be uploaded by any user with create permission or created by a hook.

2

What must happen for a stale link to expose a new file?

A file with an existing share record must be renamed rather than deleted, leaving the path-keyed share record behind. A different file must then appear at the original path; the old public link will serve it using the original link's password and expiry settings.

3

How can administrators identify potentially affected shares?

Look for share links whose original files were renamed and whose links now return 404 because the original path is empty. If a file has subsequently been created at one of those original paths, the stale link may expose that file.

4

What can be done before patching?

Avoid renaming files that have public share links; remove the share record before renaming when possible. Review stale links associated with renamed files and ensure no unrelated file is created at their original paths.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203