Junglewise Threat Intelligence

CVE-2026-37637: Alexantr filemanager remote code execution in filemanager.php

CVE-2026-37637 · Severity: info · CVSS 9.8 · Published 2026-06-29

Executive brief

Alexantr filemanager is a web-based tool used for managing files on a server. A security vulnerability in version 1.0 allows remote attackers to upload and execute malicious code, which could lead to a complete takeover of the web server and unauthorized access to all stored data.

Technical details

A Remote Code Execution (RCE) vulnerability exists in Alexantr filemanager v1.0. The flaw is located within the filemanager.php component, which fails to properly validate or restrict file uploads. A remote, unauthenticated attacker can exploit this by uploading a malicious script (such as a PHP shell) to the server and then accessing it directly via a web request. Successful exploitation allows for arbitrary command execution with the privileges of the web server user.

Affected products

  • Alexantr filemanager 1.0

Timeline

  • 2026-06-29: disclosed: Initial disclosure and CVE assignment.
  • 2026-06-29: advisory: NVD publication date.

References