云虫漏洞库

CVE-2026-82237 - filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared path — via re-upload, another user with create permission, or a hook — the stale public share link serves that new file under the original link's password and expiry s - 漏洞详情

漏洞编号:CVE-2026-82237

风险等级:低危

漏洞来源:CVE

CVE 编号:CVE-2026-82237

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-459

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared path — via re-upload, another user with create permission, or a hook — the stale public share link serves that new file under the original link's password and expiry settings, unexpectedly exposing it.

相关链接

相关漏洞

« 返回首页