CVE-2026-54089
filebrowser
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server directly can impersonate any user - including admin - by sending a single forged HTTP header. No credentials are required. Additionally, specifying a non-existent username causes the server to automatically create a new user account, providing an account creation primitive with no authorization. This...
- CVSS
- 9.1
- EPSS
- 0.43% 35.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.26