CVE-2026-30933
EUVD-2026-1054310.03.2026, 18:18
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| filebrowser | filebrowser | 𝑥 ≤ 1.2.9 |
| filebrowser | filebrowser | 1.2.1:stable |
| filebrowser | filebrowser | 1.3.0:beta |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.