{"id":"CVE-2026-35604","aliases":["GHSA-v9w4-gm2x-6rvf","GO-2026-5659"],"url":"https://o3.security/vulnerability/CVE-2026-35604","summary":"File Browser share links remain accessible after Share/Download permissions are revoked","details":"File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticated users. The public share download handler does not re-check the share owner's current permissions. This vulnerability is fixed in 2.63.1.","published":"2026-04-07T16:22:51.557Z","modified":"2026-08-12T03:51:44.373030357Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/filebrowser/filebrowser/v2","fixedVersion":"2.63.1"}],"fix":{"url":"https://github.com/filebrowser/filebrowser/pull/5888","label":"filebrowser/filebrowser#5888"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35604.json"},{"type":"ADVISORY","url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-v9w4-gm2x-6rvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35604"},{"type":"FIX","url":"https://github.com/filebrowser/filebrowser/pull/5888"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.373030357Z"}}