<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 02:01:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-273679</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-273679</link>
      <description>EUVD-2026-273679</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-273679</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27611</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27611</link>
      <description>&lt;p&gt;FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in the details of the share, which is accessible to anyone with JUST THE SHARE LINK, even without the password. Versions 1.1.3-stable and 1.2.6-beta fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in the details of the share, which is accessible to anyone with JUST THE SHARE LINK, even without the password. Versions 1.1.3-stable and 1.2.6-beta fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27611</guid>
    </item>
    <item>
      <title>GHSA-8vrh-3pm2-v4v6 — FileBrowser Quantum: Password Protection Not Enforced on Shared File Links</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8vrh-3pm2-v4v6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gtsteffaniak/filebrowser/backend&lt;/p&gt;
&lt;p&gt;### Summary
When users share password-protected files, the recipient can completely bypass the password and still download the file.&lt;/p&gt;
&lt;p&gt;### Details
This happens because the API returns a direct download link in the details of the share, which is accessible to anyone with JUST THE SHARE LINK, even without the password.&lt;/p&gt;
&lt;p&gt;### PoC
1. As an authenticated user, create a share for a file, with a password specified in &amp;#34;Optional password&amp;#34; (make sure to allow anonymous access as the PoC doesn&amp;#39;t explain how to do this on a share that requires login, but it is also possible to do on a share that requires login, with some small tweaks to the API request)
2. Copy the first link (the clipboard WITHOUT an arrow) because the second one just completely skips the password without any effort required, which was mentioned in another vulnerability (https://github.com/filebrowser/filebrowser/security/advisories/GHSA-3v48-283x-f2w4)&lt;/p&gt;
&lt;p&gt;Now, the link that was copied should look like:
https://yourdomain/public/share/yoursharehash
example:
https://example.com/public/share/ngCZzArOyFHUQBmfbvP-pA&lt;/p&gt;
&lt;p&gt;Now, make a API request with any api client to GET 
https://yourdomain/public/api/shareinfo?hash=(the share hash from the link)
example:
https://example.com/public/api/shareinfo?hash=ngCZzArOyFHUQBmfbvP-pA&lt;/p&gt;
&lt;p&gt;If curl is preferred, a (command line based API client), here&amp;#39;s the command:
`curl &amp;#39;https://yourdomain/public/api/shareinfo?hash=yoursharehash&amp;#39; -H &amp;#39;Accept: */*&amp;#39;`
example:
`curl &amp;#39;https://example.com/public/api/s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gtsteffaniak/filebrowser/backend&lt;/p&gt;
&lt;p&gt;### Summary
When users share password-protected files, the recipient can completely bypass the password and still download the file.&lt;/p&gt;
&lt;p&gt;### Details
This happens because the API returns a direct download link in the details of the share, which is accessible to anyone with JUST THE SHARE LINK, even without the password.&lt;/p&gt;
&lt;p&gt;### PoC
1. As an authenticated user, create a share for a file, with a password specified in &amp;#34;Optional password&amp;#34; (make sure to allow anonymous access as the PoC doesn&amp;#39;t explain how to do this on a share that requires login, but it is also possible to do on a share that requires login, with some small tweaks to the API request)
2. Copy the first link (the clipboard WITHOUT an arrow) because the second one just completely skips the password without any effort required, which was mentioned in another vulnerability (https://github.com/filebrowser/filebrowser/security/advisories/GHSA-3v48-283x-f2w4)&lt;/p&gt;
&lt;p&gt;Now, the link that was copied should look like:
https://yourdomain/public/share/yoursharehash
example:
https://example.com/public/share/ngCZzArOyFHUQBmfbvP-pA&lt;/p&gt;
&lt;p&gt;Now, make a API request with any api client to GET 
https://yourdomain/public/api/shareinfo?hash=(the share hash from the link)
example:
https://example.com/public/api/shareinfo?hash=ngCZzArOyFHUQBmfbvP-pA&lt;/p&gt;
&lt;p&gt;If curl is preferred, a (command line based API client), here&amp;#39;s the command:
`curl &amp;#39;https://yourdomain/public/api/shareinfo?hash=yoursharehash&amp;#39; -H &amp;#39;Accept: */*&amp;#39;`
example:
`curl &amp;#39;https://example.com/public/api/s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8vrh-3pm2-v4v6</guid>
    </item>
  </channel>
</rss>
