CVE-2026-37067
Received Received - Intake

Incorrect Access Control in Veno File Manager Allows Log Extraction

Vulnerability report for CVE-2026-37067, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: MITRE

Description

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-28
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
veno_file_manager_project veno_file_manager 4.4.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect access control issue in Veno File Manager Project version 4.4.9. It allows an unauthenticated attacker to extract all application logs from a specified date onward by sending a specially crafted POST request to the /vfm-admin/admin-panel/view/save-cvs.php file.

Detection Guidance

Check for unusual POST requests targeting /vfm-admin/admin-panel/view/save-cvs.php. Monitor logs for unauthorized access attempts or large data exfiltration from application logs.

Impact Analysis

An attacker could gain access to sensitive log data without authentication, potentially exposing confidential information, system activities, or user actions stored in the logs. This could lead to further exploitation or privacy breaches.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA by exposing sensitive personal or health data stored in logs. Unauthorized access to such data may result in legal penalties, loss of trust, and regulatory fines.

Mitigation Strategies

Restrict access to /vfm-admin/admin-panel/view/save-cvs.php via server configuration. Update Veno File Manager to a patched version if available. Implement authentication for admin-panel endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-37067. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart