What is CVE-2026-73613?
CVE-2026-73613 is a vulnerability in filebrowser versions before 2.63.19 involving the TUS upload cache eviction mechanism. It allows authenticated users with only Create permission to delete arbitrary files outside their designated scope by exploiting a symlink swap on an ancestor directory. Upgrading filebrowser to version 2.63.19 or later mitigates this issue.
Azərbaycanca: CVE-2026-73613 filebrowser proqramında TUS yükləmə keşinin təmizlənmə mexanizmində olan bir zəiflikdir. Bu, yalnız "Create" icazəsi olan autentifikasiya olunmuş istifadəçilərə öz səlahiyyət dairəsindən kənarda yerləşən faylları silməyə imkan verir. Zəiflikdən qorunmaq üçün filebrowser-i ən azı 2.63.19 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which mechanism of filebrowser was CVE-2026-73613 identified?
CVE-2026-73613 was identified in the TUS upload cache eviction mechanism of the filebrowser application.
To which version should filebrowser be updated to mitigate CVE-2026-73613?
To mitigate CVE-2026-73613, it is recommended to upgrade filebrowser to version 2.63.19 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.