PT-2026-40446 · Efw · Efw

CVE-2026-44260

·

Published

2026-05-12

·

Updated

2026-05-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions efw4.X versions prior to 4.08.010
Description The readonly flag in the 'efw:elFinder' JSP tag is intended to prevent file modifications. When protected=true, the elfinder checkRisk() function ensures the client sends readonly=true to match the session value. However, no event handler verifies the readonly value before executing write operations. Consequently, the flag only affects client-side UI elements and response metadata. An attacker can bypass the UI and send requests directly to perform file operations regardless of the readonly setting.
Recommendations Update to version 4.08.010.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44260
GHSA-5454-QHRF-VCVH

Affected Products

Efw