CVE-2026-25890Disclosure(filebrowser / filebrowser)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/) to the path, the authorization check fails to match the rule, while the underlying filesystem resolves the path correctly, granting unauthorized access to restricted files. This vulnerability is fixed in 2.57.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-10)
  • 3 total mentions across 2 days

Affected systems

Products
filebrowser

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Technical Details · 2026-02-10: 202-0902-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-091
General1
2026-02-102
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-25890 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an… https://www.cve.org/CVERecord?id=CVE-2026-25890

    Post summary

    The post cites a CVE record for a file‑management feature in File Browser but offers no additional technical, exploit, or mitigation details.

    00010194
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25890 File Browser Authentication Bypass via Malformed Path Manipulation Before 2.57.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25890

    Post summary

    The text announces CVE-2026-25890, describing an authentication bypass in File Browser through malformed path manipulation on versions prior to 2.57.1.

    0000065
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25890: CVE-2026-25890: The Double-Slash Bypass in File Browser A high-severity path traversal and authorization bypass vulnerability exists in File Browser versions prior to 2.57.1. Due to improper URL normalization settings in the Gorilla Mu... https://cvereports.com/reports/CVE-2026-25890

    Post summary

    The advisory announces a high‑severity path traversal and authorization bypass in File Browser versions before 2.57.1 due to URL normalization issues, but provides no PoC, exploit code, or patch information.

    0000038
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---

Explore more