File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler in File Browser applies default user permissions via d.settings.Defaults.Apply(user), then strips only Admin. The Execute permission and Commands list from the default user template are not stripped. When an administrator has enabled signup, server-side execution, and set Execute=true in the default user template, any unauthenticated user who self-registers inherits shell execution capabilities and can run arbitrary commands on the server. This issue has been patched in version 2.62.2.
References
| Link | Resource |
|---|---|
| https://github.com/filebrowser/filebrowser/releases/tag/v2.62.2 | Product Release Notes |
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f | Exploit Mitigation Vendor Advisory |
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f | Exploit Mitigation Vendor Advisory |
Configurations
History
06 Apr 2026, 20:41
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| First Time |
Filebrowser
Filebrowser filebrowser |
|
| References | () https://github.com/filebrowser/filebrowser/releases/tag/v2.62.2 - Product, Release Notes | |
| References | () https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f - Exploit, Mitigation, Vendor Advisory |
02 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f - |
01 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 21:17
Updated : 2026-04-06 20:41
NVD link : CVE-2026-34528
Mitre link : CVE-2026-34528
CVE.ORG link : CVE-2026-34528
JSON object : View
Products Affected
filebrowser
- filebrowser
CWE
CWE-269
Improper Privilege Management
