CVE-2026-92247: synaptikcms synaptik-cms Admin File Manager file-manager.php rename unrestricted upload
A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.3.5 is able to mitigate this issue. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
synaptikcms/synaptik-cms Admin File Manager (admin/file-manager.php)to a version that resolves this vulnerability.Fixed in 1.3.5 - Compensating control
Because the attack can be initiated remotely and allows unrestricted upload, restrict network access to the affected Admin File Manager functionality (admin/file-manager.php) so it is not reachable from untrusted networks (e.g., via firewall/ACL/WAF rules).
Event History
Frequently Asked Questions
Which deployments are affected and what version fixes the issue?
synaptik-cms versions up to and including 1.3.4.4 are affected in the Admin File Manager's rename function in admin/file-manager.php. Upgrading to version 1.3.5 mitigates the issue.
What level of access does an attacker need?
The issue can be initiated remotely, but the supplied severity vector indicates high privileges are required. No user interaction is required.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.