CVE-2026-72593
Last modified
CVE-2026-72593 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the server filesystem.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the server filesystem.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| dulldusk | phpfm | <= 1.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-72593?
How severe is CVE-2026-72593?
How do I fix CVE-2026-72593?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72588A user enumeration vulnerability in bluewave-labs/Checkmate …5.3
- CVE-2026-72589An OS command injection vulnerability in alseambusher/cronta…9.8
- CVE-2026-7259In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.…6.5
- CVE-2026-72590An OS command injection vulnerability in alseambusher/cronta…9.8
- CVE-2026-72591A server-side request forgery (SSRF) vulnerability in gabehf…7.7
- CVE-2026-72592An unrestricted file upload vulnerability in dulldusk/phpfm …9.8
- CVE-2026-72594A stored cross-site scripting (XSS) vulnerability in lobehub…7.6
- CVE-2026-72595A broken access control vulnerability in BadChoice Handesk a…8.1
- CVE-2026-72596A broken access control vulnerability in Ghost Foundation Gh…8.1
- CVE-2026-72597A server-side request forgery vulnerability in Friendica thr…6.5
- CVE-2026-72598A server-side request forgery vulnerability in Apioo Fusio 8…6.5
- CVE-2026-72599An SQL injection vulnerability in e107 2.4.0 allows unauthen…9.8
Are you affected by CVE-2026-72593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
