Security Advisory

CVE-2026-72835

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-14 11:35:40
Last updated 2026-08-14 18:03:52
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope.