CVE-2026-25890

HIGH

Filebrowser < 2.57.1 - Incorrect Authorization

Title source: rule

Description

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/) to the path, the authorization check fails to match the rule, while the underlying filesystem resolves the path correctly, granting unauthorized access to restricted files. This vulnerability is fixed in 2.57.1.

Exploits (2)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-25890
nomisec WORKING POC
by mbanyamer · poc
https://github.com/mbanyamer/CVE-2026-25890-FileBrowser-Access-Control-Bypass

Scores

CVSS v3 8.1
EPSS 0.0001
EPSS Percentile 2.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-863 CWE-706
Status published
Products (2)
filebrowser/filebrowser < 2.57.1
filebrowser/filebrowser 0 - 2.57.1Go
Published Feb 09, 2026
Tracked Since Feb 18, 2026