← back
CVE-2026-72593criticalCWE-306

dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8
exploitation probability
observed exploitation
nono source reports it
A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the server filesystem.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
dulldusk · phpfm