---
id: CVE-2026-72839
title: >-
  filebrowser through 2.63.16 fails to properly restrict scope and permissions
  when self-signup is enabled with default CreateUserDir setting
summary: >-
  filebrowser through 2.63.16 fails to properly restrict scope and permissions
  when self-signup is enabled with default CreateUserDir setting.
  Unauthenticated attackers can register accounts that inherit the server root
  scope with full cre…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-266
published: '2026-08-13'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72839'
references:
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-6759-996p-gpj6
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/filebrowser-through-privilege-escalation-via-signup
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-6759-996p-gpj6
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00574
epssPercentile: 0.45095
ingestedAt: '2026-09-08T21:11:12.277Z'
---

## Overview

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
