ZeroHour

CVE-2026-37072

niche

Incorrect Access Control in Veno File Manager 4.4.9

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-37072 is an improper access control flaw (CWE-284) in the admin-head-updates.php script of Veno File Manager, a self-hosted PHP file management application. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the issue is reachable over the network without credentials or user interaction, meaning an unauthenticated request to the affected admin script can bypass the intended access check. An attacker exploiting it gains unauthorized access to administrative functionality, with the critical 9.8 score reflecting potentially high impact on confidentiality, integrity, and availability. Anyone running Veno File Manager 4.4.9 is affected; the disclosure specifies only 4.4.9 and no broader version range. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a ~0.4% chance of exploitation within 30 days.

What to do: No fixed version is listed in the available data, so monitor the vendor for a patched release and apply it as soon as one is published. In the interim, restrict access to the Veno File Manager admin area (e.g., web-server authentication or IP allowlisting) and check whether admin-head-updates.php is reachable without authentication on your deployment.

Affected
Veno File Manager Project Veno File Manager4.4.9 (only version specified in the disclosure; other affected ranges not given)
Estimated exposure
nicheon the order of a few thousand deployments (clearly an estimate; no install counts in source data) — Veno File Manager is a niche commercial self-hosted PHP file manager whose marketplace sales and deployment patterns have historically been in the low thousands, and no public internet-scan or install-count data exists for it.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.