CVE-2026-29188Disclosure(filebrowser / filebrowser)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch filebrowser filebrowser systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allows authenticated users with only Create permission to delete arbitrary files and directories within their scope, bypassing the intended Delete permission restriction. Any multi-user deployment where administrators explicitly restrict file deletion for certain users is affected. This issue has been patched in version 2.61.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-732

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-05); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
filebrowser

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-07: 2Mentions · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-23: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-07: 1Technical Details · 2026-03-23: 103-0503-0703-23
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure1Patch1
2026-03-072
Disclosure1General1
2026-03-231
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `File Browser` contains a critical delete permission bypass (CVE-2026-29188) via its TUS delete endpoint. Authenticated users may delete files without proper authorization. Monitor for vendor patches. #FileBrowser #CVE #infosec https://www.pulsepatch.io/posts/cve-2026-29188-file-browser-tus-delete-endpoint-bypass

    Post summary

    The post announces CVE-2026-29188, a permission‑bypass flaw in File Browser that lets authenticated users delete files via the TUS endpoint, and urges users to watch for vendor patches.

    0000025
    2 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29188 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.… https://www.cve.org/CVERecord?id=CVE-2026-29188

    Post summary

    The text only references CVE-2026-29188 and briefly describes the file management features, providing no evidence of PoC, exploitation, patches, or detailed technical aspects.

    00000195
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29188 - Critical File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access... https://www.thehackerwire.com/vulnerability/CVE-2026-29188/ https://t.co/1uIvdVfo2g

    Post summary

    CVE‑2026‑29188 is a critical access‑control flaw in File Browser’s file‑managing interface, affecting all versions before 2.61.1. The bug allows attackers to manipulate files (upload, delete, preview, rename, edit) without proper authorization.

    0000046
    128 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29188: CRITICAL] File Browser addressed an access control vulnerability in the TUS protocol DELETE endpoint before version 2.61.1, enabling users with Create permission to delete files. Update to t...#cve,CVE-2026-29188,#cybersecurity https://cvefind.com/CVE-2026-29188

    Post summary

    The tweet alerts readers to CVE‑2026‑29188, an access‑control vulnerability in File Browser’s TUS DELETE endpoint, and advises updating to the fixed 2.61.1 version.

    0000049
    596 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29188 Authenticated File Deletion Bypass in File Browser Prior to 2.61.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29188

    Post summary

    The provided snippet announces CVE-2026-29188, detailing an authenticated file deletion bypass affecting File Browser versions prior to 2.61.1, and links to a vulnerability details page.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---

Explore more