OVERVIEW CVE-2026-35607 is a privilege escalation vulnerability in File Browser versions prior to 2.63.1. The vulnerability stems from an incomplete security fix that stripped execute permissions from user-signup accounts but failed to apply the same restrictions to accounts auto-created via proxy authentication. Users provisioned through proxy-auth login handlers are granted execution capabilities from global defaults, allowing them to execute commands despite the intended restriction of such permissions for auto-provisioned accounts. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and low privileges. An authenticated attacker can achieve high impact across confidentiality, integrity, and availability without requiring user interaction. The moderate FAUCET Risk Score of 51.0/100 reflects the elevated threat level associated with command execution capabilities. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog and is rated as inactive on threat tracking lists. The extremely low EPSS score of 0.00078 indicates minimal probability of exploitation in real-world scenarios. Organizations should prioritize patching to version 2.63.1 as part of standard vulnerability management procedures rather than emergency response protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.63.0CPE matchmatch criteria | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.