CVE-2026-73611

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.

Scoring

Severity
HIGH
CVSS base score
7.6
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.34%
CWE
CWE-613
Published
2026-08-13
Last modified
2026-08-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs