CRITICAL🇵🇱 Wersja polska

CVE-2026-29188

CVSS 9.1v3.1pub. 2026-03-05upd. 2026-03-10

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allows authenticated users with only Create permission to delete arbitrary files and directories within their scope, bypassing the intended Delete permission restriction. Any multi-user deployment where administrators explicitly restrict file deletion for certain users is affected. This issue has been patched in version 2.61.1.

🤖 AI Analysis
How it works

The vulnerability results from improper access control (broken access control) in the DELETE endpoint of the TUS protocol, which is used for file uploads. The TUS protocol supports resumable file uploads, and its DELETE endpoint does not properly verify whether the calling user has Delete permission — only Create permission is checked. As a result, an authenticated user with Create permission can send DELETE requests to the TUS endpoint and delete files and directories that they would normally not have the right to delete.

Impact

An attacker with Create permission can permanently delete any files and directories within their scope, bypassing the access control policy established by the administrator. This can lead to data loss and violation of the integrity and availability of stored resources.

Mitigation & patch

File Browser should be updated to version 2.61.1 or later, where the vulnerability has been patched. Details available in the official release: https://github.com/filebrowser/filebrowser/releases/tag/v2.61.1

Who is affected

File Browser (filebrowser/filebrowser) in versions prior to 2.61.1. Affects only multi-user deployments where administrators explicitly restrict delete permissions for specific users.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Filebrowser

    APP
    Filebrowser
    < 2.61.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-32760CRITICAL10.0PL ✓same product

File Browser: niezabezpieczona rejestracja konta administratora bez uwierzytelnienia

CVE-2023-39612CRITICAL9.0PL ✓same product

XSS w FileBrowser umożliwia eskalację uprawnień do Administratora

CVE-2026-35604HIGH8.2same product

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files wit...

CVE-2026-35585HIGH7.5same product

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files wit...

CVE-2026-35607HIGH8.1same product

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files wit...