CVE-2026-32760General(filebrowser / filebrowser)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch filebrowser filebrowser systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-registration (signup = true) is enabled and the default user permissions have perm.admin = true. The signup handler blindly applies all default settings (including Perm.Admin) to the new user without any server-side guard that strips admin from self-registered accounts. The signupHandler is supposed to create unprivileged accounts for new visitors. It contains no explicit user.Perm.Admin = false reset after applying defaults. If an administrator (intentionally or accidentally) configures defaults.perm.admin = true and also enables signup, every account created via the public registration endpoint is an administrator with full control over all files, users, and server settings. This issue has been resolved in version 2.62.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • General: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-20)
  • 8 total mentions across 4 days

Affected systems

Products
filebrowser

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-17: 2Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-20: 3PoC Mentioned / Linked · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-19: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 203-1703-1803-1903-20
Signal classification4 categories
General
337.5%
Patch
225.0%
PoC
225.0%
Disclosure
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-172
Disclosure1Patch1
2026-03-181
PoC1
2026-03-192
General1PoC1
2026-03-203
General2Patch1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 10.0 CVSS logic flaw in File Browser (CVE-2026-32760) grants unauthenticated users automatic admin rights upon signup. Update to 2.62.0 now. #FileBrowser #CVE #CyberSecurity #InfoSec #PrivilegeEscalation #Vulnerability #CloudSecurity #RCE https://securityonline.info/instant-hijack-critical-10-cvss-file-browser-flaw-cve-2026-32760/ https://t.co/dlJD16nsPf

    Post summary

    The post reports a critical logic flaw (CVE‑2026‑32760) in File Browser that allows unauthenticated users to gain admin rights, and urges users to update to 2.62.0 to remediate the issue.

    01101931.4K
    10.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32760 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below,… https://www.cve.org/CVERecord?id=CVE-2026-32760

    Post summary

    The brief excerpt simply lists CVE-2026-32760, describing the File Browser's file‑management capabilities and noting affected versions, without providing deeper vulnerability details or operational information.

    00000117
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32760 - File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin Intel Report: https://ift.tt/pvNkDQU

    Post summary

    The report notes that CVE‑2026‑32760 allows any user to gain admin rights via self‑registration when default permissions permit, but no PoC, exploit code, or patch details are shared.

    0000027
    334 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32760: CRITICAL] File Browser, a file managing interface, had a cyber security vulnerability allowing unauthenticated users to register as full administrators in versions 2.61.2 and below. Update t...#cve,CVE-2026-32760,#cybersecurity https://cvefind.com/CVE-2026-32760

    Post summary

    A critical vulnerability (CVE-2026-32760) was disclosed in File Browser, enabling unauthenticated users to become administrators; users are advised to update to mitigate the issue.

    0000049
    604 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-32760: File Browser Self Registration G... Default admin perms + signup enabled = instant root for anyone who can hit /api/signup - classic config footgun with pe... https://zerodaysignal.com/vulnerability/CVE-2026-32760 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reports that CVE‑2026‑32760 can grant root by hitting /api/signup when default admin permissions are enabled, and it links to a ZeroDaySignal page that likely hosts a PoC.

    0000062
    154 followersView on X
  • PulsePatch.io@pulsepatchio
    General

    An `unspecified file browser application` is vulnerable to admin privilege escalation (CVE-2026-32760) via user signup when default permissions are misconfigured. Review your access controls. #infosec #privilegeescalation #websecurity https://www.pulsepatch.io/posts/cve-2026-32760-file-browser-admin-privilege-escalation

    Post summary

    The post highlights that an unspecified file browser app is vulnerable to admin privilege escalation through default permission misconfiguration during user signup, with no PoC, patch, or evidence of active exploitation provided.

    0000032
    1 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #FileBrowser: disponibile #PoC per lo sfruttamento della CVE-2026-32760 Rischio: 🔴 Tipologia 🔸 Privilege Escalation 🔗 https://www.acn.gov.it/portale/w/file-browser-disponibile-poc-per-lo-sfruttamento-vulnerabilita-cve-2026-32760 ⚠ Importante aggiornare i software interessati https://t.co/xw4w6iFix6

    Post summary

    A PoC for CVE-2026-32760 is available and a patch is recommended, with the vulnerability classified as Privilege Escalation.

    0000052
    608 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Instant Hijack: Critical 10.0 CVSS File Browser Flaw Grants Automatic Admin Rights https://securityonline.info/instant-hijack-critical-10-cvss-file-browser-flaw-cve-2026-32760/

    Post summary

    The headline announces a newly discovered critical file browser vulnerability (CVSS 10.0) that allows attackers to automatically gain administrative rights, without indicating any PoC, exploit tool, or active exploitation reports.

    0000061
    70 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---

Explore more