Server-Side Request Forgery Vulnerability in elFinder File Manager
CVE-2026-81889

8.6HIGH

Key Information:

Vendor

Studio-42

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-81889?

The elFinder file manager has a security flaw that enables server-side request forgery through improper handling of URL uploads in the PHP implementation. Specifically, when PHP cURL is not available, the method used for fetching remote contents can be exploited by an attacker to bypass protections intended to restrict server requests. This occurs when a URL upload is processed, allowing a malicious actor to manipulate DNS responses in a way that causes sensitive internal data to be exposed. The flaw has been addressed in version 2.1.70, which rectifies the validation issues, thus safeguarding against unauthorized access.

Affected Version(s)

elFinder < 2.1.70

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.