CVE-2026-54097
HIGHFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
Title source: cnaDescription
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, a low-privileged authenticated user of filebrowser (with create + delete permissions in their own isolated scope) can silently destroy share-link records belonging to any other user — including the administrator — by performing a legitimate DELETE on a file in their own directory whose logical path happens to be a byte-prefix of another user's stored share.Link.Path. The file contents of the victim are not exposed, but the victim's share links are irrevocably wiped. This vulnerability is fixed in 2.63.6.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/filebrowser/filebrowser/security/advisories/GHSA-5ww9-jg6q-38r7
X_Refsource_Misc x_refsource_misc
https://github.com/filebrowser/filebrowser/commit/0231b7ebdfbe77a6c54027d30c4856c3fd81ee4d
X_Refsource_Misc x_refsource_misc
https://github.com/filebrowser/filebrowser/releases/tag/v2.63.6
Scores
CVSS v4
7.2
EPSS
0.0041
EPSS Percentile
33.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (3)
filebrowser/filebrowser
0 - 1.11.0Go
filebrowser/filebrowser
0 - 2.63.6Go
filebrowser/filebrowser
< 2.63.6
Published
Jun 25, 2026
Tracked Since
Jun 26, 2026