CVE-2026-82236
LOW
NVD
CVSS Score
3.1
Severity
LOW
Published
Aug 28, 2026
Vendor
unknown
Description
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.