CVE-2026-54091: Filebrowser Path Rebase Auth Bypass

Path-based authorization rules are evaluated against a potentially rebased path without resolving it back to the expected original absolute scope. This can cause deny rules to be silently bypassed if the filesystem root is unexpectedly changed (e.g., in a public directory share).

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-54091-filebrowser-path-rebase-auth-bypass --engine opengrep

Description

Path-based authorization rules are evaluated against a potentially rebased path without resolving it back to the expected original absolute scope. This can cause deny rules to be silently bypassed if the filesystem root is unexpectedly changed (e.g., in a public directory share).