CVE-2026-25890
HIGHFilebrowser < 2.57.1 - Incorrect Authorization
Title source: ruleDescription
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/) to the path, the authorization check fails to match the rule, while the underlying filesystem resolves the path correctly, granting unauthorized access to restricted files. This vulnerability is fixed in 2.57.1.
Exploits (2)
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-25890
nomisec
WORKING POC
by mbanyamer · poc
https://github.com/mbanyamer/CVE-2026-25890-FileBrowser-Access-Control-Bypass
Scores
CVSS v3
8.1
EPSS
0.0001
EPSS Percentile
2.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-863
CWE-706
Status
published
Products (2)
filebrowser/filebrowser
< 2.57.1
filebrowser/filebrowser
0 - 2.57.1Go
Published
Feb 09, 2026
Tracked Since
Feb 18, 2026