SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90930

MEDIUM · CVSS 6.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

File Browser versions up to 2.63.23 are vulnerable due to improper handling of symbolic links, which allows authenticated users to bypass established deny rules and access restricted files. This flaw can lead to unauthorized reading and overwriting of sensitive files, posing a risk to data integrity and confidentiality. Organizations using this software should prioritize remediation to mitigate potential exploitation by malicious insiders or compromised accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90930
Severity
MEDIUM
CVSS
6.8
EPSS
N/A

Original NVD Description

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by accessing them through in-scope symbolic link aliases that resolve to denied paths.