Moderate severityNVD Advisory· Published Jul 20, 2026· Updated Jul 21, 2026
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
CVE-2026-54685
Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the /api/auth/login authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a 401/403 response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gtsteffaniak/filebrowser/backendGo | < 0.0.0-20260317230626-af08800667b8 | 0.0.0-20260317230626-af08800667b8 |
Affected products
2- Range: <1.3.2-beta
- Range: <1.3.2-beta
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-7789-65hx-f26wghsaADVISORY
- github.com/gtsteffaniak/filebrowser/commit/af08800667b874620edc6f44c3e2e64fec7abd85ghsax_refsource_MISCWEB
- github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.2-betaghsax_refsource_MISCWEB
- github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f26wghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.