CVE-2026-35604
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
07/04/2026
Last modified:
16/04/2026
Description
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticated users. The public share download handler does not re-check the share owner's current permissions. This vulnerability is fixed in 2.63.1.
Impact
Base Score 4.0
8.20
Severity 4.0
HIGH
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | 2.63.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



