CVE-2026-37072
nicheIncorrect Access Control in Veno File Manager 4.4.9
CVE-2026-37072 is an improper access control flaw (CWE-284) in the admin-head-updates.php script of Veno File Manager, a self-hosted PHP file management application. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the issue is reachable over the network without credentials or user interaction, meaning an unauthenticated request to the affected admin script can bypass the intended access check. An attacker exploiting it gains unauthorized access to administrative functionality, with the critical 9.8 score reflecting potentially high impact on confidentiality, integrity, and availability. Anyone running Veno File Manager 4.4.9 is affected; the disclosure specifies only 4.4.9 and no broader version range. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.4% chance of exploitation within 30 days.
What to do: No fixed version is listed in the available data, so monitor the vendor for a patched release and apply it as soon as one is published. In the interim, restrict access to the Veno File Manager admin area (e.g., web-server authentication or IP allowlisting) and check whether admin-head-updates.php is reachable without authentication on your deployment.
| Veno File Manager Project Veno File Manager | 4.4.9 (only version specified in the disclosure; other affected ranges not given) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.