CVE-2026-72837
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Aug 14, 2026
Vendor
unknown
Description
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.