Executive brief
Veno File Manager Project is a web-based file management application used for storing and organizing files. An authenticated attacker with rename permissions can exploit a flaw in the file renaming function to overwrite the application's configuration file, causing it to reset super administrator credentials to default values. This allows the attacker to take complete control of the system without requiring additional administrative access.
Technical details
The vulnerability exists in the Actions::renameFile() function, which fails to properly validate or restrict which files can be renamed. An authenticated attacker with 'rename' permission can send a specially crafted POST request to the rename endpoint, targeting the application's configuration file. By renaming this critical file, the attacker triggers a configuration rebuild that resets the super administrator account credentials to default values. This is a post-authentication privilege escalation attack that requires only basic 'rename' file permissions, not administrative access.
Affected products
- Veno File Manager Project 4.4.9
Timeline
- 2026-08-27: disclosed
- other: CVE-2026-37071 assigned