Low severity3.1NVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026
CVE-2026-61874
CVE-2026-61874
Description
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
Affected products
1- Range: <2.63.17
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.