Junglewise Threat Intelligence

CVE-2026-37073: Veno File Manager Project unauthenticated email sending in admin endpoint

CVE-2026-37073 · Severity: medium · CVSS 5.3 · Published 2026-08-27

Technologies: Veno File Manager Project. Vendors: Veno File Manager Project.

Executive brief

Veno File Manager Project is a web-based file management application. An unauthenticated attacker can send emails through the application's configured SMTP server by making a direct POST request to an administrative endpoint, potentially enabling spam campaigns or phishing attacks from a trusted email source without authorization.

Technical details

This vulnerability is an incorrect access control flaw in the /vfm-admin/ajax/sendfiles.php endpoint of Veno File Manager Project 4.4.9. The endpoint fails to properly validate authentication or authorization before processing email-sending requests, allowing unauthenticated attackers to craft POST requests with appropriate parameters and headers to send emails through the application's configured SMTP server. No authentication bypass or specific user interaction is required—the vulnerable endpoint is directly reachable over the network. An attacker can abuse this to send arbitrary emails from the application's trusted email account, facilitating spam, phishing, or credential harvesting campaigns. The vendor has not yet issued a patch as of the CVE publication date.

Affected products

  • Veno File Manager Project Veno File Manager Project 4.4.9

Timeline

  • 2026-08-27: disclosed

References

Related threats