CVE-2026-90930

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by accessing them through in-scope symbolic link aliases that resolve to denied paths.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 13:19

Updated : 2026-09-14 15:17


NVD link : CVE-2026-90930

Mitre link : CVE-2026-90930

CVE.ORG link : CVE-2026-90930


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')