CVE-2026-37071
nicheAuthenticated Privilege Escalation via File Rename in Veno File Manager 4.4.9
Veno File Manager 4.4.9 contains an improper privilege management flaw (CWE-269) in its Actions::renameFile() function that allows a file rename operation to be abused to compromise the super administrator account. An authenticated user holding the 'rename' permission can send a specially crafted POST request to the affected rename endpoint that renames the application's configuration file, triggering a configuration rebuild that resets the super administrator credentials to their default values. An attacker can then log in as the super administrator using those default credentials and take over the application. Only installations running Veno File Manager 4.4.9 are affected. The flaw is rated critical (CVSS 3.1 score 9.8), but no public proof-of-concept or in-the-wild exploitation is known, it is not listed in CISA KEV, and EPSS assigns a 0.4% probability of exploitation within 30 days.
What to do: Upgrade to the vendor's patched release as soon as one is available (the advisory does not name a fixed version, so check the Veno File Manager changelog), and in the meantime restrict the 'rename' permission to fully trusted users only. Audit installations for a renamed configuration file and reset the super administrator credentials away from their defaults, and monitor for suspicious POST requests to the file-rename endpoint.
| Veno File Manager Project Veno File Manager | 4.4.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.