CVE-2026-72839Critical· 9.8▾ Midnightfilebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full cre…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.6%
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100619High· 8.8Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly
CVE-2025-66296High· 8.8Grav is a file-based Web platform
CVE-2025-13806High· 7.3A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT
CVE-2025-10644Critical· 9.4Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
CVE-2025-10608Medium· 6.3A vulnerability was detected in Portabilis i-Educar up to 2.10
CVE-2025-10209Medium· 5.4A security flaw has been discovered in Papermerge DMS up to 3.5.3