Authenticated Command Execution Vulnerability in Pheditor by Pheditor
CVE-2026-54540
8.8HIGH
What is CVE-2026-54540?
Pheditor, a PHP-based file manager and editor, contains a vulnerability that allows authenticated users with terminal permissions to bypass the command allowlist configured in the application. This is due to the absence of adequate restrictions on shell command substitutions. As a result, an attacker can execute arbitrary shell commands with the same privileges as the web server user. The issue has been resolved in version 2.0.5, which addresses the command execution vulnerability by enforcing stricter command validations.
Affected Version(s)
pheditor < 2.0.5
