PT-2026-40444 · Elfinder · Elfinder

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2026-44258

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions efw4.X versions prior to 4.08.010
Description The elfinder checkRisk() function validates target and targets for path traversal and home containment but fails to validate the dst parameter used by elfinder paste. This allows an attacker to copy or move files from the home directory to an arbitrary destination by using a base64-encoded traversal path, bypassing the protected=true security control. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 4.08.010.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-44258

Affected Products

Elfinder