CVE-2026-44542 Details
Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This affects public/api/resources and public/api/resources/bulk. This vulnerability is fixed in 1.3.1-stable and 1.3.9-beta.
A path traversal vulnerability has been identified in FileBrowser Quantum versions prior to 1.3.1-stable and 1.3.9-beta. The issue arises because attacker-controlled path inputs are concatenated with a trusted base path before proper sanitization. This flaw allows traversal sequences, such as '../', to escape the designated shared directory. Consequently, an unauthenticated attacker with a valid public share hash that includes delete permissions can remove arbitrary files outside the shared directory, within the storage scope configured by the share owner. The vulnerability impacts both the public/api/resources endpoint and the public/api/resources/bulk endpoint.
Users can update to FileBrowser Quantum versions 1.3.1-stable or 1.3.9-beta to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-fwj3-42wh-8673 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-fwj3-42wh-8673 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gtsteffaniak filebrowser quantum | < 1.3.1 < 1.3.9 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 15, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |