LOWCVSS 3.1Vulnerability

CVE-2026-82237

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared path — via re-upload, another user with create permission, or a hook — the stale public share link serves that new file under the original link's password and expiry settings, unexpectedly exposing it.

Properties

severity
LOW
cvss_severity
LOW
cvss_score
3.1
retrieved_at
2026-09-25T15:10:03+00:00
score
3.1
last_source
NVD
cve_id
CVE-2026-82237
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
signal_observed_at
2026-09-25T15:10:03+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
published_at
2026-08-28T12:16:33.587
last_modified
2026-09-24T20:34:34.170

Related Entities (2)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Incomplete Cleanup

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82237 (CVSS 3.1) — Ninja Signal Threat Intelligence | Ninja Signal