CVE-2026-44542(gtsteffaniak / filebrowser_quantum)
LOWCVSS 9.1 · CRITICALImmediate actions
- Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This affects public/api/resources and public/api/resources/bulk. This vulnerability is fixed in 1.3.1-stable and 1.3.9-beta.
Sources & remediation
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- filebrowser_quantum
Affected systems
Deep dive
CPE platform detail2 entries
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | gtsteffaniak | filebrowser_quantum | - | - | - |
| App | gtsteffaniak | filebrowser_quantum | - | - | - |
