Intel

AIKIDO-2026-10018

github.com/filebrowser/filebrowser/v2 is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 12, 2026

67

Medium Risk

This Affects:

GOgithub.com/filebrowser/filebrowser/v2
2.0.0 - 2.53.0
Fixed in 2.53.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Insufficient Session Validation, where sensitive actions like password changes and command execution can be performed by an authenticated user without validating the session's authority for sensitive actions, such as by prompting for password re-entry; this lack of validation allows attackers to exploit multiple broken access control vulnerabilities or local access to an unlocked device to perform unauthorized high-privilege actions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/filebrowser/filebrowser/v2 is vulnerable to Improper Access Control in versions 2.0.0 - 2.53.0.

How to fix this

Upgrade the github.com/filebrowser/filebrowser/v2 library to the patch version.