ZeroHour

CVE-2026-37071

niche

Authenticated Privilege Escalation via File Rename in Veno File Manager 4.4.9

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

Veno File Manager 4.4.9 contains an improper privilege management flaw (CWE-269) in its Actions::renameFile() function that allows a file rename operation to be abused to compromise the super administrator account. An authenticated user holding the 'rename' permission can send a specially crafted POST request to the affected rename endpoint that renames the application's configuration file, triggering a configuration rebuild that resets the super administrator credentials to their default values. An attacker can then log in as the super administrator using those default credentials and take over the application. Only installations running Veno File Manager 4.4.9 are affected. The flaw is rated critical (CVSS 3.1 score 9.8), but no public proof-of-concept or in-the-wild exploitation is known, it is not listed in CISA KEV, and EPSS assigns a 0.4% probability of exploitation within 30 days.

What to do: Upgrade to the vendor's patched release as soon as one is available (the advisory does not name a fixed version, so check the Veno File Manager changelog), and in the meantime restrict the 'rename' permission to fully trusted users only. Audit installations for a renamed configuration file and reset the super administrator credentials away from their defaults, and monitor for suspicious POST requests to the file-rename endpoint.

Affected
Veno File Manager Project Veno File Manager4.4.9
Estimated exposure
nichelikely low thousands of deployments at most (self-hosted PHP file manager typically deployed on individual small sites) — No public install counts or internet-exposure scan data exist for this commercial, self-hosted PHP file manager, so the estimate rests on its typical deployment pattern of small, per-site installations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.