Unrated severityNVD Advisory· Published Aug 27, 2026
CVE-2026-37066
CVE-2026-37066
Description
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: =4.4.9
Patches
Vulnerability mechanics
References
1- veno.comnvd
News mentions
0No linked articles in our index yet.