What is CVE-2026-73611?
CVE-2026-73611 affects File Browser versions 2.50.0 through 2.63.21, which fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. This allows attackers with a previously valid token to access protected routes and administrative endpoints indefinitely, and potentially exchange expired tokens. Users should update to a patched version and ensure proper JWT validation.
Azərbaycanca: CVE-2026-73611, File Browser-in 2.50.0-dən 2.63.21-ə qədər olan versiyalarında, proksi autentifikasiyası qeyri-standart çıxış səhifəsi ilə konfiqurasiya edildikdə JWT-nin bitmə müddətini yoxlamaması ilə bağlıdır. Bu zəiflik, əvvəllər etibarlı token əldə etmiş hücumçulara qorunan marşrutlara və inzibati son nöqtələrə qeyri-məhdud giriş imkanı verə bilər. İstifadəçilərə proqramı yeniləmək və JWT doğrulamasını düzgün icra etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which File Browser versions are affected by CVE-2026-73611?
CVE-2026-73611 affects File Browser versions 2.50.0 through 2.63.21.
What can an attacker gain by exploiting CVE-2026-73611?
An attacker with a previously valid token can gain indefinite access to protected routes and administrative endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.