A vulnerability identified as critical has been detected in FileBrowser up to 2.63.18. This affects an unknown part of the component Tus Resumable-Upload Patch Endpoint. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2026-72838. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.