What is CVE-2026-72837?
This vulnerability arises because File Browser versions before 2.63.20 fail to properly enforce createUserDir isolation in proxy and hook authentication paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users. Immediate update to version 2.63.20 or later is recommended.
Azərbaycanca: Bu boşluq File Browser-in 2.63.20-dən əvvəlki versiyalarında proxy və hook autentifikasiyası zamanı createUserDir izolyasiyasının düzgün tətbiq edilməməsindən qaynaqlanır. Etibarlı upstream autentifikasiya məlumatları olan hücumçular digər istifadəçilərin fayllarını oxuya, dəyişdirə, silə və paylaşa bilərlər. Dərhal 2.63.20 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of File Browser are affected by CVE-2026-72837?
File Browser versions before 2.63.20.
What can attackers do by exploiting the createUserDir isolation flaw?
Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.