SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-82236

LOW · CVSS 3.1 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

File Browser versions 2.63.6 to 2.63.23 are vulnerable due to inadequate cleanup of public share links when a privileged user deletes a shared file from another user. This flaw allows attackers to exploit lingering share links to access new, unrelated content uploaded to the same path without requiring authentication. Organizations using these versions should prioritize remediation to prevent unauthorized access to sensitive data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82236
Severity
LOW
CVSS
3.1
EPSS
0.28%

Original NVD Description

File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.