Junglewise Threat Intelligence

CVE-2026-37069: Veno File Manager absolute path disclosure

CVE-2026-37069 · Severity: medium · CVSS 5.3 · Published 2026-08-27

Vendors: Veno.

Executive brief

Veno File Manager is a web-based file management application. An unauthenticated attacker can send a simple GET request to a publicly accessible endpoint to discover the complete filesystem path where the application is installed, exposing internal system architecture details that can aid further attacks.

Technical details

The vulnerability is an absolute path disclosure (information disclosure) in the file /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php. An unauthenticated attacker can access this endpoint via a simple GET request without authentication, and the server returns the full filesystem path to the application installation directory. This path information can be leveraged by an attacker to plan further exploitation by understanding the application's internal directory structure and confirming installed components.

Affected products

  • Veno File Manager 4.4.9

Timeline

  • 2026-08-27: disclosed

References