CVE-2026-23849 | filebrowser up to 2.54.x /api/login timing discrepancy (GHSA-43mm-m3h2-3prc / EUVD-2026-3287)
A vulnerability identified as problematic has been detected in filebrowser up to 2.54.x. This vulnerability affects unknown code of the file /api/login. The manipulation leads to observable timing discrepancy.
This vulnerability is documented as CVE-2026-23849. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.