CVE-2026-90930: File Browser through 2.63.23 Path Traversal via Symlink Alias

Published Sep 14, 2026
·
Updated

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by accessing them through in-scope symbolic link aliases that resolve to denied paths.

Affected Software

1 affected component
File Browser<=2.63.23

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade File Browser to a version that resolves this vulnerability.

    Fixed in 2.63.23Patch Path Traversal via Symlink Alias
  2. Compensating control

    For File Browser, restrict authenticated users’ ability to access/serve arbitrary files so they cannot exploit in-scope symbolic link aliases to reach rule-denied paths.

Event History

Sep 14, 2026
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated File Browser user can exploit it if they can access an in-scope symbolic link whose target is a path denied by configured rules. Exploitation requires bypassing the deny rules through that symlink alias.

2

What is the impact of a successful exploit?

An attacker can read and overwrite files that the File Browser deny rules are intended to block. The vulnerability does not indicate an availability impact.

3

Are default deployments affected?

The issue depends on deny rules and symbolic links that resolve from an allowed in-scope path to a denied target. The provided information does not establish whether a default configuration includes those conditions.

4

What should be checked while remediation is pending?

Review configured deny rules and identify in-scope symbolic links whose resolved targets fall under denied paths. Such links can provide authenticated users a route to read or overwrite files that should be blocked.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203