File Browser versions prior to 2.63.1 contain a privilege escalation vulnerability in which revoked Share and Download permissions do not invalidate previously generated share links. An authenticated user with administrative privileges can revoke another user's sharing capabilities, but existing public links created by that user remain fully functional for unauthenticated access, allowing unauthorized file downloads despite the permission revocation. The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The impact is significant, affecting both confidentiality and integrity of file data, though system availability is not compromised. An authenticated attacker can exploit this without user interaction to maintain unauthorized access to shared files after permissions have been administratively revoked. There are currently no known active exploitations or public exploit code associated with this vulnerability, and it is not tracked on the CISA Known Exploited Vulnerabilities list. The EPSS score of 0.0006 indicates minimal real-world exploitation probability at this time. Organizations running File Browser should prioritize updating to version 2.63.1 or later to revoke the accessibility of previously generated share links upon permission changes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.63.1CPE matchmatch criteria | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.