All verified exploits

CVE-2026-34528 RCE via Self-Registration Execute Permission Inheritance

Deterministic critical File Browser Added cve-verified-cve-2026-34528

Detects File Browser instances before version 2.62.2 where the signup handler copies default user permissions — including Execute=true and the Commands allowlist — to self-registered accounts. The patch for CVE-2026-32760 only stripped the Admin flag but left Execute and Commands intact. An unauthenticated attacker can register, authenticate, and run arbitrary shell commands on the server via the /api/command/ WebSocket endpoint. The fix explicitly sets Execute=false and Commands=[] for self-registered users.

Is your app exploitable through CVE-2026-34528?

Scan your domain free