Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35607

29
FAUCET Score

OVERVIEW CVE-2026-35607 is a privilege escalation vulnerability in File Browser versions prior to 2.63.1. The vulnerability stems from an incomplete security fix that stripped execute permissions from user-signup accounts but failed to apply the same restrictions to accounts auto-created via proxy authentication. Users provisioned through proxy-auth login handlers are granted execution capabilities from global defaults, allowing them to execute commands despite the intended restriction of such permissions for auto-provisioned accounts. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and low privileges. An authenticated attacker can achieve high impact across confidentiality, integrity, and availability without requiring user interaction. The moderate FAUCET Risk Score of 51.0/100 reflects the elevated threat level associated with command execution capabilities. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog and is rated as inactive on threat tracking lists. The extremely low EPSS score of 0.00078 indicates minimal probability of exploitation in real-world scenarios. Organizations should prioritize patching to version 2.63.1 as part of standard vulnerability management procedures rather than emergency response protocols.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.63.0CPE matchmatch criteria
cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 19th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/filebrowser/filebrowser/v2Fixed in: 2.63.1

Vendor Advisories (1)

goGHSA-7526-j432-6ppphigh

File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

Apr 8, 2026

References

github.com / filebrowser/filebrowser/pull/5890
Patch
github.com / filebrowser/filebrowser/security/advisories/GHSA-7526-j432-6ppp
ExploitVendor Advisory