Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a critical vulnerability in the file management tool Filebrowser that could allow unauthenticated attackers to gain unrestricted access to all files on a server if self-signup is enabled with default settings. The issue stems from improper scope and permission restrictions, enabling attackers to create accounts with server-wide administrative privileges.
- Unauthenticated users can gain full server file access.
- Confirms broad, unauthorized server access potential.
- Verify if self-signup is enabled and review permissions.
Attack Path
How an attacker could exploit the issue
Unauthenticated attackers can exploit this vulnerability by registering an account on a Filebrowser instance where self-signup is enabled. This allows them to create user accounts that inherit the server's root directory scope, granting them full permissions to create, modify, delete, rename, share, and download any file on the server.
- Entry condition: Self-signup is enabled.
- Trigger point: Registering a new user account.
- Resulting risk: Unrestricted access to all server files.
Live Threat
Current exploitation, exposure, and threat context
When self-signup is enabled with default settings, unauthenticated attackers could register accounts that gain unrestricted access to all files on the server.
- Server files could be exposed.
- Unauthenticated users could register accounts.
- Unrestricted access to all files.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Filebrowser instances with self-signup enabled. Owners of Filebrowser deployments, likely within application or infrastructure teams, must identify affected systems, confirm their exposure and criticality, and then plan remediation. Coordination with any vendor providing Filebrowser as a service will also be necessary.
- Determine accountable Filebrowser owners.
- Verify self-signup enabled and network exposure.
- Plan remediation based on asset criticality.