CVE-2026-54685

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.
Configurations

No configuration.

History

21 Jul 2026, 16:17

Type Values Removed Values Added
References () https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f26w - () https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f26w -

20 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 15:16

Updated : 2026-07-22 20:50


NVD link : CVE-2026-54685

Mitre link : CVE-2026-54685

CVE.ORG link : CVE-2026-54685


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy