CVE-2026-35606Disclosure(filebrowser / filebrowser)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch filebrowser filebrowser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the Perm.Download permission flag. All three other content-serving endpoints (/api/raw, /api/preview, /api/subtitle) correctly verify this permission before serving content. A user with download: false can read any text file within their scope through two bypass paths. This vulnerability is fixed in 2.63.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
filebrowser

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-07: 2Patch / Workaround · 2026-04-07: 104-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35606 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resource… https://www.cve.org/CVERecord?id=CVE-2026-35606 ----- Traducción: CVE-2026-35606 Fil… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑35606 with a brief overview and a link to its CVE.org page, offering no additional technical or exploitation details.

    0000022
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35606 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resource… https://www.cve.org/CVERecord?id=CVE-2026-35606

    Post summary

    The excerpt provides a brief overview of CVE-2026-35606, indicating a vulnerability in File Browser with a referenced fix in version 2.63.1, but offers no additional details or evidence of exploitation.

    00000152
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---

Explore more