CVE-2026-37066
Last modified
CVE-2026-37066 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-37066?
How severe is CVE-2026-37066?
How do I fix CVE-2026-37066?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-3703A flaw has been found in Wavlink NU516U1 251208. This affect…9.8
- CVE-2026-3704A vulnerability has been found in Wavlink NU516U1 251208. Th…7.2
- CVE-2026-3705A vulnerability was found in code-projects Simple Flight Tic…9.8
- CVE-2026-3706A vulnerability was determined in mkj Dropbear up to 2025.89…3.7
- CVE-2026-37064User enumeration in /vfm-admin/ajax/usr-check.php in Veno Fi…5.3
- CVE-2026-37065Veno File Manager Project 4.4.9 is vulnerable to Arbitrary F…9.1
- CVE-2026-37067Incorrect access control in /vfm-admin/admin-panel/view/save…5.3
- CVE-2026-37068Arbitrary file write in /vfm-admin/index.php?section=transla…8.1
- CVE-2026-37069Absolute Path Disclosure in /vfm-admin/assets/zipstream/gran…5.3
- CVE-2026-3707A vulnerability was identified in MrNanko webp4j up to 1.3.x…5.3
- CVE-2026-37070Incorrect access control in /vfm-admin/ajax/streamvid.php in…6.5
- CVE-2026-37071Arbitrary File Rename Leading to Privilege Escalation in Act…9.8
Are you affected by CVE-2026-37066?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
