Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Filebrowser Insecure Password Handling (CVE-2025-52997)

Vulnerability Overview

All user accounts authenticate towards a Filebrowser instance with a password. A missing password policy and brute-force protection makes it impossible for administrators to properly secure the authentication process.

  • Type of Vulnerability: Weak Authentication
  • Fixed in Version: 2.34.1
  • CVE ID: CVE-2025-52997
  • CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • CVSS Base Score: 5.9 (Medium)

Recommended Countermeasure

We recommend to update to Filebrowser version 2.34.1 or later and configure fail2ban according to the documentation.

Links

Full Security Advisory

Credits

Mathias Tausig (SBA Research)