CVE-2026-34528

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler in File Browser applies default user permissions via d.settings.Defaults.Apply(user), then strips only Admin. The Execute permission and Commands list from the default user template are not stripped. When an administrator has enabled signup, server-side execution, and set Execute=true in the default user template, any unauthenticated user who self-registers inherits shell execution capabilities and can run arbitrary commands on the server. This issue has been patched in version 2.62.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*

History

06 Apr 2026, 20:41

Type Values Removed Values Added
CPE cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*
First Time Filebrowser
Filebrowser filebrowser
References () https://github.com/filebrowser/filebrowser/releases/tag/v2.62.2 - () https://github.com/filebrowser/filebrowser/releases/tag/v2.62.2 - Product, Release Notes
References () https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f - () https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f - Exploit, Mitigation, Vendor Advisory

02 Apr 2026, 14:16

Type Values Removed Values Added
References () https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f - () https://github.com/filebrowser/filebrowser/security/advisories/GHSA-x8jc-jvqm-pm3f -

01 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 21:17

Updated : 2026-04-06 20:41


NVD link : CVE-2026-34528

Mitre link : CVE-2026-34528

CVE.ORG link : CVE-2026-34528


JSON object : View

Products Affected

filebrowser

  • filebrowser
CWE
CWE-269

Improper Privilege Management