What is CVE-2026-72838?
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies exceeding the declared upload length to exhaust disk space, so users should immediately update to version 2.63.19 or later.
Azərbaycanca: FileBrowser-in 2.63.19-dən əvvəlki versiyalarında TUS davam etdirilə bilən yükləmə PATCH endpoint-ində elan edilmiş Upload-Length tətbiq edilmədiyi üçün autentifikasiyalı istifadəçilər diskdə ixtiyari məlumat yaza bilərlər. Bu boşluq hücumçulara elan edilmiş yükləmə həcmini aşan sorğu gövdələri göndərərək disk sahəsini doldurmağa imkan verir, buna görə istifadəçilər dərhal 2.63.19 versiyasına və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which FileBrowser versions are affected by CVE-2026-72838?
FileBrowser versions before 2.63.19 are affected.
What can an authenticated attacker achieve by exploiting CVE-2026-72838?
The attacker can exhaust disk space by sending oversized request bodies exceeding the declared Upload-Length to the TUS resumable-upload PATCH endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.