Remote Code Execution Vulnerability in Responsive FileManager by Trippo
CVE-2026-5482

9.3CRITICAL

Key Information:

Vendor

Tecrail

Vendor
CVE Published:
15 June 2026

What is CVE-2026-5482?

The Responsive FileManager by Trippo is vulnerable due to its dialog.php endpoint, which permits unauthenticated users to upload any type of file without restrictions. This flaw can lead to severe security risks, including Remote Code Execution, allowing attackers to execute arbitrary code on the server. The vulnerability exists in version 9.14.0 of the product, and it is crucial for users to take immediate action to mitigate any potential risks.

Affected Version(s)

Responsive FileManager 0 <= 9.14.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.