CVE-2026-35607General(filebrowser / filebrowser)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch filebrowser filebrowser systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users created via the signup handler. The same fix was not applied to the proxy auth handler. Users auto-created on first successful proxy-auth login are granted execution capabilities from global defaults, even though the signup path was explicitly changed to prevent execution rights from being inherited by automatically provisioned accounts. This vulnerability is fixed in 2.63.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
filebrowser

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 104-0704-09
Signal classification3 categories
General
133.3%
Patch
133.3%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-072
General1Patch1
2026-04-091
PoC1
Full discourse3 posts
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #FileBrowser: disponibili #PoC per lo sfruttamento delle CVE-2026-35604 e CVE-2026-35607 Rischio: 🔴 Tipologia 🔸 Elevation of Privilege 🔸 Authentication Bypass 🔗 https://www.acn.gov.it/portale/w/file-browser-disponibili-poc-per-lo-sfruttamento-di-alcune-vulnerabilita ⚠ Importante aggiornare i software inte… https://t.co/aTseelvKsL

    Post summary

    The post announces publicly available PoC code for CVE‑2026‑35604 and CVE‑2026‑35607, lists the vulnerability types, and urges software updates, but does not describe active exploitation or detailed exploit tools.

    00020123
    620 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-35607 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in c… https://www.cve.org/CVERecord?id=CVE-2026-35607 ----- Traducción: CVE-2026-35607 Fil… http://infoflow.cloud`

    Post summary

    A short post linking to a CVE record with minimal detail, lacking any concrete proof of concept, exploit, or mitigation.

    0000022
    67 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-35607 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in c… https://www.cve.org/CVERecord?id=CVE-2026-35607

    Post summary

    The post notes a CVE-2026-35607 vulnerability in File Browser, highlighting that a patch is available in version 2.63.1, with no mention of PoC, exploit code, or active exploitation.

    00000146
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---

Explore more