filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-12 12:16
Updated : 2026-07-13 20:03
NVD link : CVE-2026-61874
Mitre link : CVE-2026-61874
CVE.ORG link : CVE-2026-61874
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
