Unrated severityNVD Advisory· Published Aug 27, 2026
CVE-2026-37069
CVE-2026-37069
Description
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: =4.4.9
Patches
Vulnerability mechanics
References
1- veno.comnvd
News mentions
0No linked articles in our index yet.