CVE-2026-32759 affects File Browser versions 2.61.2 and below, where its TUS resumable upload handler fails to validate the Upload-Length header, allowing authenticated users to supply a negative value. This flaw instantly satisfies upload completion, triggering after_upload exec hooks with empty files. Rated 8.1 HIGH on the CVSS scale, this vulnerability can lead to Denial of Service, cache inconsistency, or, with the enableExec flag, remote command injection amplification. The attack complexity is low, requiring only an authenticated user. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.61.2CPE matchmatch criteria | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.