What is CVE-2026-72839?
CVE-2026-72839 is a vulnerability in filebrowser up to version 2.63.16 where self-signup with the default CreateUserDir setting fails to properly restrict scope and permissions. This allows unauthenticated attackers to register accounts with full server root access, including create, modify, delete, rename, share, and download capabilities. It is recommended to disable self-signup or update the application immediately.
Azərbaycanca: CVE-2026-72839, özünəqeyd (self-signup) aktiv olduqda filebrowser 2.63.16 və əvvəlki versiyalarında əhatə dairəsi (scope) və icazələrin düzgün məhdudlaşdırılmaması zəifliyidir. Bu, autentifikasiya olunmamış hücumçulara server kök əhatəsi ilə tam idarəetmə icazələri (yaratmaq, silmək, dəyişdirmək, paylaşmaq, yükləmək) əldə etməyə imkan verir. Dərhal self-signup funksiyasını deaktiv etmək və ya proqramı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Under what condition can CVE-2026-72839 be exploited?
This vulnerability can be exploited only when the self-signup feature is enabled in the filebrowser application.
What permissions can an attacker gain by exploiting CVE-2026-72839?
An attacker can gain full control permissions with server root scope, including the ability to create, delete, modify, share, and download.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.