A vulnerability, which was classified as problematic, was found in gtsteffaniak FileBrowser up to 1.3.2. This impacts the function bcrypt of the file /api/auth/login of the component Password Comparison. Executing a manipulation of the argument Username can lead to incorrect comparison.

This vulnerability is registered as CVE-2026-54685. It is possible to launch the attack remotely. No exploit is available.