Junglewise Threat Intelligence

CVE-2026-37067: Veno File Manager Project authentication bypass in save-cvs.php

CVE-2026-37067 · Severity: medium · CVSS 5.3 · Published 2026-08-27

Technologies: Veno File Manager Project. Vendors: Veno File Manager Project.

Executive brief

Veno File Manager Project is a web-based file management application. An unauthenticated attacker can bypass access controls to extract application logs from the server via a specially crafted request, potentially exposing sensitive operational data, user activities, and system information contained in those logs.

Technical details

The vulnerability is an access control bypass in the /vfm-admin/admin-panel/view/save-cvs.php endpoint in Veno File Manager Project 4.4.9. The vulnerable component fails to properly authenticate or authorize requests before processing them, allowing an unauthenticated attacker to submit a specially crafted POST request to extract application logs from a specified date forward. This is a classic broken authentication / authorization flaw that exposes sensitive diagnostic and operational logs without requiring prior authentication. An attacker can retrieve logs remotely via the network without credentials or user interaction.

Affected products

  • Veno File Manager Project Veno File Manager Project 4.4.9

Timeline

  • 2026-08-27: disclosed

References

Related threats