LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-72839

Published
CVSS9.8
Severitycritical
WeaknessCWE-266
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-72839

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-72839.