CVE-2026-61874 Details
Description
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
A vulnerability exists in Filebrowser versions prior to 2.63.17, where the application fails to properly normalize file paths before deleting shared directories. This issue allows authenticated users to delete a directory share using a path with a trailing slash, leaving the share link inactive but still stored. When the same directory is recreated, the public share link is reactivated and exposes the new contents, bypassing the intended share deletion process.
Users can update to Filebrowser version 2.63.17 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 12, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-pp88-jhwj-5qh5 | CISA-ADP | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://github.com/filebrowser/filebrowser/commit/be23ab3a15bf957928ecfed88de5ab67850c1b9c | [email protected] | Source CodeVendor |
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-pp88-jhwj-5qh5 | [email protected] | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/filebrowser-before-stale-public-share-via-trailing-slash-delete | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| filebrowser | < 2.63.17 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 12, 2026 | New CVE Received | [email protected] |
Volerion