SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90929

HIGH · CVSS 8.1 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

File Browser versions 2.5.0 to 2.63.23 are vulnerable due to an incorrect authorization flaw in the direct-upload endpoint, allowing authenticated users with only Create and Modify permissions to delete directories they should not have access to. This can lead to unauthorized data loss, as the cleanup process fails to enforce proper permission checks, potentially affecting the integrity of sensitive files. Organizations using these versions should prioritize remediation to prevent potential exploitation by malicious insiders or compromised accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90929
Severity
HIGH
CVSS
8.1
EPSS
N/A

Original NVD Description

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a target that is an existing directory; a POST with ?override=true aimed at a directory fails inside writeFile (a directory cannot be opened for writing) and the failure-cleanup path then calls Fs.RemoveAll on the request path, recursively deleting the entire tree. This cleanup is gated by neither the Perm.Delete permission nor the checkDescendants rule walk applied by the delete and patch handlers, so an authenticated non-administrator holding only the default Create and Modify permissions can delete directories they are not authorized to delete, including rule-denied files within them. Deletion remains confined to the user's scope because ScopedFs.RemoveAll still enforces the scope guard. The faulty cleanup was introduced in v2.5.0; no patched version is available.