CVE-2026-72835Medium· 6.8▾ Sunlitfilebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can reques…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.5%
filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34510Medium· 5.3OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
CVE-2026-93709Medium· 5.3Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler compares the request path against the layout directory name as text, while the…
CVE-2026-57441High· 8.4MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault
CVE-2026-89768Medium· 5.5kernel: fs: fix user path of nested backing files (CVE-2026-89768)
CVE-2026-85978Critical· 9.8An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform
CVE-2026-73019Medium· 4.3Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.