CVE-2026-44542

Published: Mag 14, 2026 Last Modified: Mag 15, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,1
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: high

Description

AI Translation Available

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This affects public/api/resources and public/api/resources/bulk. This vulnerability is fixed in 1.3.1-stable and 1.3.9-beta.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0064
Percentile
0,7th
Updated

EPSS Score Trend (Last 6 Days)

22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Files Or Directories Read Files Or Directories Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies: AI/ML
View CWE Details
Application

Filebrowser Quantum by Gtsteffaniak

Version Range Affected
To 1.3.9 (exclusive)
cpe:2.3:a:gtsteffaniak:filebrowser_quantum:*:beta:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Filebrowser Quantum by Gtsteffaniak

Version Range Affected
To 1.3.1 (exclusive)
cpe:2.3:a:gtsteffaniak:filebrowser_quantum:*:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-fwj3-42wh-…
https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-fwj3-42wh-…