CVE-2026-55579 is a hardcoded credential vulnerability in Pheditor, a single-file editor and file manager written in PHP. Affected versions from 2.0.1 through before 2.0.6 ship with a built-in default password of "admin," with the corresponding SHA-512 hash embedded in the application code. The product also lacks a mechanism to require password change on first login. In deployments where the default credential remains in use, an unauthenticated remote attacker can authenticate to the application and obtain full access to administrative functionality, including the file editor, file upload capability, and terminal features. This access can be leveraged for arbitrary file read and write operations and can ultimately result in remote code execution on the underlying server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script (exploit.py) plus supporting documentation (README.md, ANALYSIS.md, EVIDENCE.md). It is not part of a larger exploitation framework. The exploit targets CVE-2026-55579 in Pheditor, a web-based PHP file manager/editor, where a hardcoded default password ('admin') allows unauthenticated attackers to log in and then abuse authenticated functionality for remote code execution. Main exploit flow in exploit.py: (1) validate target URL, (2) authenticate by POSTing the default password to the Pheditor endpoint, (3) maintain the returned session cookie with urllib/http.cookiejar, (4) fetch the main page and regex-extract the CSRF token from JavaScript, and then either (5a) send action=terminal requests with an attacker-controlled command to execute arbitrary OS commands, or (5b) send multipart action=upload requests to place arbitrary files on the server. The script uses only Python standard library modules (argparse, urllib, cookiejar, regex, os, socket, ssl) and includes custom exception classes, timeout handling, verbose logging, and CLI options for password override, upload path, and remote directory. Exploit capabilities are substantial: authenticated command execution as the web server user, reverse-shell delivery by passing a shell one-liner as the command, arbitrary file upload to web-accessible directories, and—per repository documentation—abuse of Pheditor editor actions for arbitrary file read/write. The provided examples show use against /pheditor.php, extraction of a token variable from HTML/JavaScript, execution of commands like id and uname -a, upload of shell.php to /var/www/html/, and reading /etc/passwd via action=open. Overall, this is an operational PoC exploit for a web/network attack path. It is more than a detector: it automates login, session handling, token extraction, command execution, and file upload against vulnerable Pheditor deployments that still use the default hardcoded credential.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.