File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
File Browser versions before 2.63.20 contain a critical authentication isolation flaw where the createUserDir mechanism fails to properly enforce user boundaries in proxy and hook-based authentication paths. This vulnerability allows attackers who possess valid upstream authentication credentials to bypass user isolation controls and gain unauthorized access to other users' files on the same server. The vulnerability is particularly dangerous because it affects the auto-provisioning workflow—a common deployment pattern—and exploits improper scope assignment at the server root level, enabling read, modify, delete, and file-sharing operations across user boundaries. Organizations running vulnerable File Browser instances in multi-tenant or shared environments face significant risk of data breach, unauthorized modification, and privilege escalation.
While this CVE maps to CWE-284 (Improper Access Control), the attack patterns fall outside mapped MITRE ATT&CK techniques, presenting a detection gap. Casky's Claude-powered analysis would identify this vulnerability through extended reasoning across related attack patterns: Privilege Escalation (T1548) via improper authentication scope, Lateral Movement (T1570) through cross-user file access, and Data from Local System (T1005) via unauthorized file reads. A practitioner using Casky would observe findings highlighting authentication context confusion in proxy/hook flows, insufficient boundary validation in auto-provisioning logic, and server-level scope assignments that override per-user isolation. The platform would correlate configuration anomalies—such as overly permissive createUserDir settings or authentication paths that bypass isolation checks—with potential exploitation indicators, enabling defenders to detect both misconfigurations and active exploitation attempts targeting multi-user deployments.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-72837. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation