CVE-2026-72593
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
10/08/2026
Last modified:
10/08/2026
Description
A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, and uploading files anywhere on the server filesystem.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL


