Authenticated Command Execution Vulnerability in Pheditor by Pheditor
CVE-2026-54540

8.8HIGH

Key Information:

Vendor

Pheditor

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-54540?

Pheditor, a PHP-based file manager and editor, contains a vulnerability that allows authenticated users with terminal permissions to bypass the command allowlist configured in the application. This is due to the absence of adequate restrictions on shell command substitutions. As a result, an attacker can execute arbitrary shell commands with the same privileges as the web server user. The issue has been resolved in version 2.0.5, which addresses the command execution vulnerability by enforcing stricter command validations.

Affected Version(s)

pheditor < 2.0.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.