PatchSiren cyber security CVE debrief
CVE-2026-46410 gtsteffaniak CVE debrief
CVE-2026-46410 is a high-severity vulnerability in FileBrowser Quantum, a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. The CVSS score is 8.7, indicating a high severity level. The vulnerability class is related to sensitive information leaks. The affected product is FileBrowser Quantum. The likely operational impact is sensitive information disclosure.
- Vendor
- gtsteffaniak
- Product
- filebrowser
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-21
Who should care
Users of FileBrowser Quantum versions prior to 1.3.2-stable and 1.4.1-beta should apply the patches to prevent potential sensitive information leaks. Affected operators include FileBrowser Quantum administrators and users. The vulnerability-management impact is high, as the vulnerability has a high CVSS score. Security teams should prioritize patching affected instances.
Technical summary
The vulnerability affects FileBrowser Quantum versions prior to 1.3.2-stable and 1.4.1-beta. It may leak sensitive information, such as source and path. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X. The vulnerability has a high CVSS score, indicating a high severity level.
Defensive priority
High priority should be given to patching FileBrowser Quantum instances, as the vulnerability has a high CVSS score and may lead to sensitive information leaks.
Recommended defensive actions
- Apply patches to upgrade to version 1.3.2-stable or 1.4.1-beta
- Review and update inventory of FileBrowser Quantum instances
- Monitor for potential sensitive information leaks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-20T15:16:38.673Z and was last modified on 2026-07-21T15:16:34.793Z. The NVD entry is currently Received. The vulnerability affects FileBrowser Quantum versions prior to 1.3.2-stable and 1.4.1-beta. Evidence of exploitation is not currently available, but defenders should verify affected scope and severity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T15:16:38.673Z and has not been modified since then. The NVD entry is currently Received.