LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-29188

CVE-2026-29188 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: March 5, 2026

File Browser - Broken Access Control

Published: March 5, 2026Updated: March 5, 2026Remote Exploitable

Overview

File Browser < 2.61.1 contains a broken access control vulnerability caused by improper permission checks in the TUS protocol DELETE endpoint, letting authenticated users with Create permission delete arbitrary files, exploit requires user authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.1
EPSS Score: 5.9%(Probability of exploitation in next 30 days)

Impact

Authenticated users with limited permissions can delete arbitrary files, potentially causing data loss or disruption.

Mitigation

Upgrade to version 2.61.1 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

šŸ”“ CVE-2026-29188 - Critical (9.1) File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint a... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-29188/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-29188
Severity
Critical
CVSS Score
9.1
Type
broken_access_control
Status
new
EPSS
5.9%
Social Posts
1

CWE

  • CWE-284

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Score

5.9%Probability of exploitation in the next 30 days