Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-61874 1 Filebrowser 1 Filebrowser 2026-07-14 3.1 Low
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.