High severity8.8NVD Advisory· Published Aug 14, 2026
CVE-2026-72837
CVE-2026-72837
Description
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.63.20
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.