What is CVE-2026-73612?
A vulnerability in File Browser before v2.63.22 allows authenticated users to bypass path-based access controls during recursive copy, rename, and delete operations. By operating on an allowed parent directory, attackers can manipulate files in restricted descendant paths. Users should immediately update to version 2.63.22 or later.
Azərbaycanca: File Browser-un v2.63.22-dən əvvəlki versiyalarında rekursiv əməliyyatlar zamanı alt qovluqlar üçün giriş qaydalarının düzgün yoxlanılmaması zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş istifadəçilərə icazə verilən ana qovluq üzərində əməliyyat apararaq qadağan olunmuş faylları kopyalamaq, adını dəyişmək və ya silmək imkanı verir. İstifadəçilərə dərhal v2.63.22 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of File Browser are affected by CVE-2026-73612?
All versions prior to v2.63.22 are affected. Users should immediately update to version 2.63.22 or later for security.
What operations can an authenticated attacker perform by exploiting CVE-2026-73612?
During recursive copy, rename, and delete operations, they can manipulate files in restricted paths.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.