Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-37072: Veno File Manager 4.4.9 lets unauthorized users change admin settings

CVE-2026-37072 · published 7 days ago
Summary

The Veno File Manager version 4.4.9 does not properly check who can access the admin-head-updates.php page, so someone without proper rights could modify administrative settings. This could let attackers alter the system or gain higher privileges. Update to a patched version or apply the vendor's recommended configuration changes as soon as possible.

Original advisory text
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published27 Aug 2026
Updated3 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-37072 · MITRE
Monitor software like this
Free during beta