CVE-2026-30933General(filebrowser / filebrowser)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-306CWE-602

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
filebrowser

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-18: 203-18
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-30933 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password p… https://www.cve.org/CVERecord?id=CVE-2026-30933 ----- Traducción: CVE-2026-30933 Fil… http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-30933 without providing further technical information, PoC, exploits, or mitigation details.

    0000036
    60 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30933 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password p… https://www.cve.org/CVERecord?id=CVE-2026-30933

    Post summary

    The post notes CVE-2026-30933 and indicates that remediation for another CVE is incomplete, but offers no PoC, exploit details, evidence of active attacks, or patch information.

    00000199
    56.7K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---
Appfilebrowserfilebrowser1.2.1--
Appfilebrowserfilebrowser1.3.0--

Explore more