Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35604

27
FAUCET Score

File Browser versions prior to 2.63.1 contain a privilege escalation vulnerability in which revoked Share and Download permissions do not invalidate previously generated share links. An authenticated user with administrative privileges can revoke another user's sharing capabilities, but existing public links created by that user remain fully functional for unauthenticated access, allowing unauthorized file downloads despite the permission revocation. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The impact is significant, affecting both confidentiality and integrity of file data, though system availability is not compromised. An authenticated attacker can exploit this without user interaction to maintain unauthorized access to shared files after permissions have been administratively revoked. There are currently no known active exploitations or public exploit code associated with this vulnerability, and it is not tracked on the CISA Known Exploited Vulnerabilities list. The EPSS score of 0.0006 indicates minimal real-world exploitation probability at this time. Organizations running File Browser should prioritize updating to version 2.63.1 or later to revoke the accessibility of previously generated share links upon permission changes.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.63.1CPE matchmatch criteria
cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 13th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/filebrowser/filebrowser/v2Fixed in: 2.63.1

Vendor Advisories (1)

goGHSA-v9w4-gm2x-6rvfhigh

File Browser share links remain accessible after Share/Download permissions are revoked

Apr 8, 2026

References

github.com / filebrowser/filebrowser/pull/5888
Patch
github.com / filebrowser/filebrowser/security/advisories/GHSA-v9w4-gm2x-6rvf
ExploitVendor Advisory