File Browser Proxy Authentication Auto-Provisioning Execution Permission Vulnerability

Vulnerability

A vulnerability in File Browser prior to version 2.63.1 allows users auto-created through the proxy authentication process to inherit execution permissions and commands from global defaults. This issue arises because the proxy authentication handler does not apply the same restrictions as the signup handler, which prevents self-registered users from receiving execution rights. As a result, automatically provisioned accounts via proxy authentication can execute commands that were not explicitly granted by an administrator.

Impact

Users auto-provisioned through proxy authentication on first login inherit execution rights and default commands, violating the project's security policy that prohibits automatic accounts from receiving such permissions. This issue undermines the intended permission management and could lead to unauthorized command execution.

Reproduction

The vulnerability can be reproduced by configuring File Browser to use proxy authentication and enabling default commands that include execution capabilities. After logging in as an admin, a new user can be auto-created via the proxy header. The permissions for this new user will reflect the inherited execution rights and commands, demonstrating the vulnerability.

Remediation

Users can update to File Browser version 2.63.1, where this vulnerability has been fixed.

Added: Apr 7, 2026, 7:32 PM
Updated: Apr 7, 2026, 7:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
9.5
remediation
7.7
relevance
5.4
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.