LOW 2.3 NVD
CVE-2026-82236
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can a
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
References
- https://github.com/filebrowser/filebrowser/commit/0231b7eb
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-r6pg-pg54-rcr5
- https://www.vulncheck.com/advisories/file-browser-2.63.6-through-2.63.23-share-link-exposu
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-r6pg-pg54-rcr5
This low severity vulnerability with a CVSS score of 2.3 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.