Critical Security Flaw in Pheditor PHP File Manager by Pheditor
CVE-2026-55579

9.8CRITICAL

Key Information:

Vendor

Pheditor

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-55579?

Pheditor, a PHP-based single-file editor and file manager, contains a significant security vulnerability that stems from a hardcoded default password for the admin account. Versions 2.0.1 through 2.0.5 are affected, allowing attackers who exploit this flaw to gain unrestricted access to the file management system and execute arbitrary code. Notably, there is no prompt for changing the default password upon the first login, which can lead to severe security breaches, including unauthorized file access and uploads. It is crucial for users of these versions to update to 2.0.6 to mitigate this risk and secure their environments.

Affected Version(s)

pheditor >= 2.0.1, < 2.0.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.