What is CVE-2026-72834?
CVE-2026-72834 is a permission bypass vulnerability in the /api/resources endpoint of filebrowser versions before 2.63.19. The checksum query reads file contents without performing a Perm.Download check, potentially allowing unauthorized access to file data. Users should update to version 2.63.19 or later immediately.
Azərbaycanca: CVE-2026-72834, filebrowser-in 2.63.19-dan əvvəlki versiyalarında /api/resources endpoint-də icazə yan keçmə zəifliyidir. checksum sorğusu faylın məzmununu Perm.Download yoxlaması olmadan oxuyur, bu da icazəsiz fayl məzmununun əldə edilməsinə səbəb ola bilər. İstifadəçilər dərhal 2.63.19 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of filebrowser are affected by CVE-2026-72834?
CVE-2026-72834 affects filebrowser versions before 2.63.19.
What is the root cause of CVE-2026-72834?
The root cause is that the checksum query in the /api/resources endpoint reads file contents without performing a Perm.Download check.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.