File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint. | |
| Title | File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T11:28:15.147Z
Reserved: 2026-08-13T11:16:27.834Z
Link: CVE-2026-73611
No data.
Status : Received
Published: 2026-08-13T12:17:25.747
Modified: 2026-08-13T12:17:25.747
Link: CVE-2026-73611
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:15:03Z