SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-54910

HIGH · CVSS 7.7 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

FileBrowser Quantum versions prior to 1.4.3-beta are vulnerable to path traversal attacks through the `subtitlesHandler` endpoint, allowing authenticated users to manipulate the `path` and `name` query parameters without proper sanitization. This can lead to unauthorized access to sensitive files on the server, including system configuration files and credentials. Organizations using this file manager should prioritize upgrading to the patched version to mitigate the risk of data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54910
Severity
HIGH
CVSS
7.7
EPSS
0.31%

Original NVD Description

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape the storage root and set `parentDir` to any directory on the host. No existing anchor file is required. The secondary vector is the `name` parameter: it is joined with `parentDir` via `filepath.Join(parentDir, name)` without stripping directory components, allowing traversal relative to any resolved `parentDir`. Any authenticated user (regardless of role or permissions) can exploit either vector to read any text file readable by the server process, including `/etc/passwd`, SSH keys, database credentials, and JWT signing keys. Version 1.4.3-beta patches the issue.