<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:09:56.544612+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278736</id>
    <title>EUVD-2026-278736</title>
    <updated>2026-10-10T19:09:56.590591+00:00</updated>
    <content>EUVD-2026-278736</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34528</id>
    <title>fkie_cve-2026-34528</title>
    <updated>2026-10-10T19:09:56.590627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler in File Browser applies default user permissions via d.settings.Defaults.Apply(user), then strips only Admin. The Execute permission and Commands list from the default user template are not stripped. When an administrator has enabled signup, server-side execution, and set Execute=true in the default user template, any unauthenticated user who self-registers inherits shell execution capabilities and can run arbitrary commands on the server. This issue has been patched in version 2.62.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34528"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x8jc-jvqm-pm3f</id>
    <title>GHSA-x8jc-jvqm-pm3f — File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution</title>
    <updated>2026-10-10T19:09:56.590661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filebrowser/filebrowser/v2</p>
<p>## Summary</p>
<p>The `signupHandler` in File Browser applies default user permissions via `d.settings.Defaults.Apply(user)`, then strips only `Admin` (commit `a63573b`). The `Execute` permission and `Commands` list from the default user template are **not** stripped. When an administrator has enabled signup, server-side execution, and set `Execute=true` in the default user template, any unauthenticated user who self-registers inherits shell execution capabilities and can run arbitrary commands on the server.</p>
<p>## Details</p>
<p>### Root Cause</p>
<p>`signupHandler` at `http/auth.go:167–172` applies all default permissions before stripping only `Admin`:</p>
<p>```go
// http/auth.go
d.settings.Defaults.Apply(user)   // copies ALL permissions from defaults</p>
<p>// Only Admin is stripped — Execute, Commands are still inherited
user.Perm.Admin = false
// user.Perm.Execute remains true if set in defaults
// user.Commands remains populated if set in defaults
```</p>
<p>`settings/defaults.go:31–33` confirms `Apply` copies the full permissions struct including Execute and Commands:</p>
<p>```go
func (d *UserDefaults) Apply(u *users.User) {
    u.Perm = d.Perm          // includes Execute
    u.Commands = d.Commands  // includes allowed shell commands
    // ...
}
```</p>
<p>The `commandsHandler` at `http/commands.go:63–66` checks both the server-wide `EnableExec` flag and `d.user.Perm.Execute`:</p>
<p>```go
if !d.server.EnableExec || !d.user.Perm.Execute {
    // writes "Command not allowed." and returns
}
```</p>
<p>The `withUser` middlewa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x8jc-jvqm-pm3f"/>
  </entry>
</feed>
