Detects File Browser instances before version 2.62.2 where the signup handler copies default user permissions — including Execute=true and the Commands allowlist — to self-registered accounts. The patch for CVE-2026-32760 only stripped the Admin flag but left Execute and Commands intact. An unauthenticated attacker can register, authenticate, and run arbitrary shell commands on the server via the /api/command/ WebSocket endpoint. The fix explicitly sets Execute=false and Commands=[] for self-registered users.
Is your app exploitable through CVE-2026-34528?
Scan your domain free