PT-2026-84021 · Elfinder · Elfinder

CVE-2026-81890

·

Published

2026-08-31

·

Updated

2026-09-02

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions elFinder versions prior to 2.1.70
Description The netmount command is missing from the elFinderConnector::$csrfProtectedCmds list in php/elFinderConnector.class.php, which prevents the validateCsrfToken() function from being executed during this state-changing operation. In the default php/connector.minimal.php-dist configuration, FTP network mounts are enabled. This allows a cross-site request to bypass the X-elFinder-CSRF token requirement and pass attacker-controlled arguments—including protocol, host, path, port, user, pass, alias, and options—through elFinder::netmount() in php/elFinder.class.php to php/elFinderVolumeFTP.class.php. Consequently, an attacker can force the PHP server to connect to an arbitrary FTP host and port using supplied credentials and persist an attacker-chosen FTP mount within the victim's session.
Recommendations Update to version 2.1.70.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81890
GHSA-9HJF-W35W-6VX2

Affected Products

Elfinder