CVE-2026-37070
Received Received - Intake

Incorrect Access Control in Veno File Manager Allows Unauthorized File Access

Vulnerability report for CVE-2026-37070, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: MITRE

Description

Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-28
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
veno_file_manager_project veno_file_manager 4.4.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect access control issue in the Veno File Manager Project version 4.4.9. It allows an authenticated attacker to read any uploaded files by other users if they know the file path and name. The attacker can exploit this by sending a specially crafted GET request to the affected endpoint /vfm-admin/ajax/streamvid.php.

Detection Guidance

To detect this vulnerability, check if Veno File Manager 4.4.9 is installed and verify if the affected endpoint /vfm-admin/ajax/streamvid.php is accessible. Look for unauthorized file access attempts or unusual GET requests to this path. Review server logs for suspicious activity targeting this endpoint.

Impact Analysis

If you use Veno File Manager Project version 4.4.9, an attacker with valid credentials could access sensitive files uploaded by other users. This could lead to unauthorized data exposure, privacy breaches, or theft of confidential information if file paths and names are known.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other data protection regulations. Unauthorized access to personal or sensitive data may result in legal penalties, fines, or reputational damage due to failure to protect user data as required by these standards.

Mitigation Strategies

Immediately update Veno File Manager to a patched version if available. If no patch exists, restrict access to the /vfm-admin/ajax/streamvid.php endpoint via server configuration (e.g., .htaccess or firewall rules). Ensure authentication is enforced and sensitive files are not exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-37070. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart