What is CVE-2026-72836?
In FileBrowser versions before 2.63.19, the home directory ownership check during self-registration does not account for case-insensitive filesystems. When 'Signup' and 'CreateUserDir' are enabled on a case-insensitive filesystem (e.g., Windows/NTFS), this flaw can allow two self-registered users with case-different usernames to potentially share the same home directory. Users should update to version 2.63.19 immediately.
Azərbaycanca: FileBrowser 2.63.19-dan əvvəlki versiyalarda, özünü qeydiyyat (self-registration) zamanı ev qovluğu sahibliyini yoxlayarkən hərf həssaslığı olmayan fayl sistemləri nəzərə alınmır. Bu zəiflik xüsusilə Windows/NTFS kimi fayl sistemlərində "Signup" və "CreateUserDir" aktiv olduqda, iki fərqli istifadəçinin eyni qovluğa sahib ola bilməsinə şərait yaradır. İstifadəçilər ən qısa müddətdə 2.63.19 versiyasına yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which FileBrowser versions are affected by CVE-2026-72836?
This vulnerability affects all FileBrowser versions before 2.63.19.
What conditions are required to successfully exploit this vulnerability?
To exploit this vulnerability, the 'Signup' and 'CreateUserDir' features must be enabled on a case-insensitive filesystem such as Windows/NTFS.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.