CVE-2026-54685: CWE-208: Observable Timing Discrepancy in gtsteffaniak filebrowser
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.
AI Analysis
Technical Summary
The vulnerability in FileBrowser Quantum affects the authentication endpoint /api/auth/login prior to version 1.3.2-beta. When a login attempt is made with a non-existent username, the server returns a 401/403 response almost immediately. However, if the username exists, the server performs a bcrypt password hash comparison, causing a measurable delay. This timing discrepancy (CWE-208) can be exploited to enumerate valid usernames by measuring response times. The issue is patched in version 1.3.2-beta.
Potential Impact
An attacker can leverage the timing difference in authentication responses to determine whether a username exists on the system. This information disclosure can facilitate targeted attacks such as credential stuffing or brute force attacks. The vulnerability does not directly impact confidentiality, integrity, or availability beyond username enumeration.
Mitigation Recommendations
Upgrade to FileBrowser Quantum version 1.3.2-beta or later, where the timing discrepancy in the authentication endpoint has been fixed. No other mitigation is required as the patch addresses the issue directly.
CVE-2026-54685: CWE-208: Observable Timing Discrepancy in gtsteffaniak filebrowser
Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.
CVSS v3.1
Score 5.3medium
Affected software
pkg:github/gtsteffaniak/filebrowserRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in FileBrowser Quantum affects the authentication endpoint /api/auth/login prior to version 1.3.2-beta. When a login attempt is made with a non-existent username, the server returns a 401/403 response almost immediately. However, if the username exists, the server performs a bcrypt password hash comparison, causing a measurable delay. This timing discrepancy (CWE-208) can be exploited to enumerate valid usernames by measuring response times. The issue is patched in version 1.3.2-beta.
Potential Impact
An attacker can leverage the timing difference in authentication responses to determine whether a username exists on the system. This information disclosure can facilitate targeted attacks such as credential stuffing or brute force attacks. The vulnerability does not directly impact confidentiality, integrity, or availability beyond username enumeration.
Mitigation Recommendations
Upgrade to FileBrowser Quantum version 1.3.2-beta or later, where the timing discrepancy in the authentication endpoint has been fixed. No other mitigation is required as the patch addresses the issue directly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T22:53:58.561Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e33e12a4a8d598937d22d
Added to database: 07/20/2026, 14:42:41 UTC
Last enriched: 07/20/2026, 14:58:00 UTC
Last updated: 07/21/2026, 06:37:24 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.