MEDIUMVulnerability

CVE-2026-72835

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope.

Properties

severity
MEDIUM
score
6.8
epss_score
0.00338
cve_id
CVE-2026-72835
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-14T12:16:46.930
last_modified
2026-09-08T20:32:39.347
epss_percentile
0.26665

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Resolution of Path Equivalence

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72835 — Ninja Signal Threat Intelligence | Ninja Signal