Server-Side Request Forgery Vulnerability in elFinder File Manager
CVE-2026-81889
8.6HIGH
What is CVE-2026-81889?
The elFinder file manager has a security flaw that enables server-side request forgery through improper handling of URL uploads in the PHP implementation. Specifically, when PHP cURL is not available, the method used for fetching remote contents can be exploited by an attacker to bypass protections intended to restrict server requests. This occurs when a URL upload is processed, allowing a malicious actor to manipulate DNS responses in a way that causes sensitive internal data to be exposed. The flaw has been addressed in version 2.1.70, which rectifies the validation issues, thus safeguarding against unauthorized access.
Affected Version(s)
elFinder < 2.1.70
