CVE-2026-54089Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server directly can impersonate any user - including admin - by sending a single forged HTTP header. No credentials are required. Additionally, specifying a non-existent username causes the server to automatically create a new user account, providing an account creation primitive with no authorization. This is an already known issue that has been documented in the documentation for several years, but has not been documented as a vulnerability before.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-26: 1Mentions · 2026-07-10: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-10: 106-2607-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 FileBrowser, Authentication Bypass via Proxy Auth Header Forgery, #CVE-2026-54089 (Critical) -DC-Jul2026-863 https://dailycve.com/filebrowser-authentication-bypass-via-proxy-auth-header-forgery-cve-2026-54089-critical-dc-jul2026-863/

    Post summary

    The post discloses a critical authentication bypass vulnerability (CVE-2026-54089) in FileBrowser, caused by forging Proxy Auth headers.

    0000056
    218 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - File Browser proxy auth header spoofing leads to account takeover (CVE-2026-54089) File Browser is vulnerable when configured with proxy authentication (auth.method=proxy), allowing trust of upstream identity headers in the auth component. The root cause is improper authentication/authorization due to insecure reliance on client-supplied HTTP headers and missing validation that requests actually originate from a trusted proxy. An unauthenticated attacker who can reach the File Browser server directly can forge the expected auth header to impersonate any user (including admin), and can even supply a non-existent username to trigger automatic account creation. Impact includes full administrative account takeover, unauthorized user provisioning, and complete compromise of data and server-side file management actions. 👉 Affected: filebrowser >= 2.0.0-rc.1 (when auth.method=proxy) | Upgrade to No fix yet - treat as suspicious

    Post summary

    File Browser’s proxy authentication is vulnerable to header spoofing, enabling attackers to impersonate users and create accounts, potentially taking admin control; no patch is yet available.

    0000080
    231 followersView on X

Explore more