{"apiVersion":"1.0","identifier":"CVE-2026-37071","description":"Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with -reanme- permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.","publishedAt":"2026-08-27T20:17:43","lastModifiedAt":"2026-08-27T20:17:43","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-37071","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00156,"riskScore":0,"affectedProduct":"Veno File Manager","affectedVersions":"==4.4.9","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-37071","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-37071","en":"https://www.redsauce.net/en/cves/CVE-2026-37071","fr":"https://www.redsauce.net/fr/cves/CVE-2026-37071","pt":"https://www.redsauce.net/pt/cves/CVE-2026-37071","de":"https://www.redsauce.net/de/cves/CVE-2026-37071","sk":"https://www.redsauce.net/sk/cves/CVE-2026-37071","el":"https://www.redsauce.net/el/cves/CVE-2026-37071"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-37071"}}