Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-37071: Veno File Manager 4.4.9 can reset admin password
CVE-2026-37071 · published 7 days ago
Summary
The file‑manager software version 4.4.9 lets a user who can rename files change the program’s configuration file. By doing this, the system automatically rebuilds its settings and restores the super‑admin account to its default password, handing control to the attacker. Apply the vendor’s update, remove unnecessary rename rights, and change the administrator password immediately.
Original advisory text
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the...
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published27 Aug 2026
Updated3 Sep 2026
First seen27 Aug 2026
Monitor software like this
Free during beta