CVE-2026-37066 is a path traversal vulnerability in Veno File Manager Project 4.4.9 administrative request handlers. Insufficient validation of attacker-controlled path input permits a super-administrator to craft POST and GET requests that traverse outside the intended file scope and read arbitrary files accessible to the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept exploit for CVE-2026-37066 affecting Veno File Manager 4.4.9. It contains two files: a Bash exploit script (PoC.sh) and a short README describing the vulnerability. The exploit is not part of a larger framework. The Bash script performs an authenticated arbitrary file read against VFM using a valid session cookie supplied on the command line. Its workflow is straightforward: first, it sends a POST request to /vfm-admin/index.php with starting_dir=./ to alter the application's starting directory, described in comments as moving to filesystem root. Second, it sends a GET request to /vfm-admin/ajax/streamvid.php with the vid parameter set to a base64-encoded file path. The demonstrated target is vfm-admin/_content/users/users.php, but the comments indicate that any file readable by the application context may be disclosed, including application files and potentially system files depending on webserver configuration. Capabilities: authenticated arbitrary file disclosure/path traversal. The exploit does not provide code execution, persistence, or lateral movement; it is focused solely on reading files. Because it includes a working exploitation sequence with hardcoded example behavior but no flexible payload framework, the maturity is best classified as OPERATIONAL. Fingerprintable targets and observables include the VFM administrative endpoints /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php, the POST parameter starting_dir, the GET parameter vid, and the example sensitive file path vfm-admin/_content/users/users.php. The exploit requires super administrator access according to both the script comments and README, though the script also notes a related weaker use case where authenticated users may retrieve known uploaded files without the first step.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.