Description
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Veno File Manager Project 4.4.9 suffers from an incorrect access control flaw in the admin-head-updates.php file. This weakness allows an attacker who can gain any level of user authentication to execute functions reserved for administrators, potentially enabling unauthorized file modifications, configuration changes, or further exploitation of the web application. The flaw directly compromises the integrity and confidentiality of data managed by the file manager, and may also impact availability if an attacker deletes or corrupts critical files.

Affected Systems

The affected product is Veno File Manager Project version 4.4.9. No other versions or vendors are listed as impacted.

Risk and Exploitability

The vulnerability is reported as an access-control issue with no explicit severity score or exploitation probability available. It is likely exploitable via the web interface by authenticated users, meaning that once an attacker obtains basic user credentials the elevated privileges can be triggered. Because the flaw is not listed in the CISA KEV catalog and no EPSS score is provided, the current risk assessment remains uncertain but could be moderate to high for systems that expose the Veno File Manager to untrusted networks.

Generated by OpenCVE AI on August 28, 2026 at 05:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official update or patch for Veno File Manager if available
  • If no patch exists, remove or rename the vulnerable admin-head-updates.php file to prevent access
  • Restrict access to the administrative interface using IP whitelisting or VPN to limit exposure

Generated by OpenCVE AI on August 28, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Veno File Manager 4.4.9 Improper Access Control in Admin Interface
Weaknesses CWE-284

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T19:03:51.017Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37072

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:43.253

Modified: 2026-08-27T20:17:43.253

Link: CVE-2026-37072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:00:14Z

Weaknesses