CVE-2026-72839
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72839.json, https://github.com/filebrowser/filebrowser/security/advisories/GHSA-6759-996p-gpj6, https://nvd.nist.gov/vuln/detail/CVE-2026-72839, https://www.vulncheck.com/advisories/filebrowser-through-privilege-escalation-via-signup