Public proof-of-concept code has been released for three high-severity vulnerabilities in the open-source File Browser self-hosted file management application, including CVE-2026-73611, CVE-2026-73612, and CVE-2026-73613. The issues affect File Browser/File Server releases up to 2.63.21 in the broader advisory, while individual fixes were introduced in later versions, including 2.63.22 for the recursive-operations access-control flaw and 2.63.19 as unaffected for the symlink-based deletion issue.
CVE-2026-73612 allows authenticated users to bypass path-based access controls during recursive copy, rename, and delete operations, letting them manipulate restricted descendant files and directories. CVE-2026-73613 enables arbitrary out-of-scope file deletion through symlink manipulation in the TUS upload cache eviction process, potentially deleting files outside an attacker’s authorized scope with only create permissions. Separately, CVE-2026-73611 affects JWT-based proxy authentication and can allow expired tokens to be accepted and renewed under certain non-default logout configurations, creating an authentication and security-restrictions bypass risk. Organizations using File Browser have been urged to apply the latest vendor patches immediately.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-73613 states that the new CVE was received by disclosure@vulncheck.com. The vulnerability affects File Browser versions earlier than 2.63.19.
The CVE record for CVE-2026-73612 was published and updated with affected version information, description, CVSS metrics, CWE mapping, and references. The entry identifies disclosure@vulncheck.com as the source.
CSIRT Italia reported that public proof-of-concept code is available for CVE-2026-73613, CVE-2026-73612, and CVE-2026-73611 in File Browser. It also noted that the vulnerabilities had already been patched by the vendor and advised users to apply the latest security updates.
The vendor patched CVE-2026-73612, an authorization bypass in recursive copy, rename, and delete operations, with version 2.63.22 listed as unaffected. The fix enforces descendant access rules during recursive operations.
The vendor patched the out-of-scope file deletion vulnerability CVE-2026-73613, with version 2.63.19 identified as unaffected. The flaw allowed authenticated users to delete arbitrary files outside their authorized scope via symlink manipulation in the TUS cache eviction mechanism.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.