Junglewise Threat Intelligence

CVE-2026-37070: Veno File Manager Project incorrect access control in streamvid.php

CVE-2026-37070 · Severity: medium · CVSS 6.5 · Published 2026-08-27

Technologies: Veno File Manager Project. Vendors: Veno File Manager Project.

Executive brief

Veno File Manager Project is a file management application used to upload and organize documents. An authenticated attacker can bypass access controls to read files uploaded by other users if they know the file path and name, potentially exposing sensitive documents and confidential business information.

Technical details

An incorrect access control vulnerability exists in the /vfm-admin/ajax/streamvid.php endpoint of Veno File Manager Project 4.4.9. The vulnerable component fails to properly validate whether an authenticated user has permission to access files belonging to other users. An authenticated attacker can craft a specially crafted GET request containing a path and filename to retrieve any uploaded file, bypassing the intended multi-user access restrictions. No elevated privileges or user interaction is required beyond initial authentication. The vulnerability allows unauthorized information disclosure through direct enumeration of file paths.

Affected products

  • Veno File Manager Project Veno File Manager Project 4.4.9

Timeline

  • 2026-08-27: disclosed

References

Related threats