CVE-2026-37067: Veno File Manager Project Veno File Manager vulnerability
Published Aug 27, 2026
·Updated
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.
Affected Software
1 affected component
Veno File Manager Project Veno File Manager=4.4.9
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker only needs to send a specially crafted POST request to /vfm-admin/admin-panel/view/save-cvs.php. No authentication is required.
2
What information could be exposed?
The issue allows extraction of all application logs from an attacker-selected date onward.
3
Which deployments are exposed?
Deployments of Veno File Manager Project 4.4.9 are affected where the specified admin-panel endpoint is reachable by an attacker.