---
id: CVE-2026-90930
title: >-
  File Browser through 2.63.23 applies path rules to the requested lexical path
  but resolves symbolic links without reapplying rules to the target, allowing
  authenticated users to bypass deny rules
summary: >-
  File Browser through 2.63.23 applies path rules to the requested lexical path
  but resolves symbolic links without reapplying rules to the target, allowing
  authenticated users to bypass deny rules. Attackers can read and overwrite
  rule-de…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-59
vendor: filebrowser
product: filebrowser
affected:
  - filebrowser <= 2.63.23
published: '2026-09-14'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:44:42.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90930'
references:
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7w29-q235-57m9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/file-browser-through-2.63.23-path-traversal-via-symlink-alias
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7w29-q235-57m9
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.005
epssPercentile: 0.40264
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T14:17:22.121504Z'
ingestedAt: '2026-09-14T15:23:07.421Z'
---

## Overview

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by accessing them through in-scope symbolic link aliases that resolve to denied paths.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
