CVE-2026-25889Disclosure(filebrowser / filebrowser)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a case-sensitivity flaw in the password validation logic allows any authenticated user to change their password (or an admin to change any user's password) without providing the current password. By using Title Case field name "Password" instead of lowercase "password" in the API request, the current_password verification is completely bypassed. This enables account takeover if an attacker obtains a valid JWT token through XSS, session hijacking, or other means. This vulnerability is fixed in 2.57.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-10)
  • 3 total mentions across 2 days

Affected systems

Products
filebrowser

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Technical Details · 2026-02-10: 202-0902-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25889 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a … https://www.cve.org/CVERecord?id=CVE-2026-25889

    Post summary

    The text announces CVE‑2026‑25889 for File Browser, noting that versions prior to 2.57.1 allow various file operations. No additional exploitation details, patches, or PoCs are provided.

    00010187
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25889 Authentication Bypass in File Browser Before 2.57.1 via Case-Sensitive P... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25889 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    CVE-2026-25889 is an authentication bypass in File Browser versions prior to 2.57.1 caused by case‑sensitive handling. No exploit or patch information is provided in the brief announcement.

    0000059
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25889: Case Sensitive, Security Insensitive: Bypassing Auth in File Browser File Browser, the beloved Swiss Army knife for self-hosted file management, suffered from a classic logic error: it forgot that 'Password' and 'password' are not the ... https://cvereports.com/reports/CVE-2026-25889

    Post summary

    The report reveals a case‑sensitive authentication bypass in File Browser (CVE‑2026‑25889), but provides no PoC, exploit, or patch details.

    0000040
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---

Explore more