Cross-Site Request Forgery Vulnerability in elFinder Web File Manager by Studio 42
CVE-2026-81890

5.4MEDIUM

Key Information:

Vendor

Studio-42

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-81890?

The elFinder file manager for web applications has a CSRF vulnerability that affects versions before 2.1.70. Because the netmount command is not included in the CSRF protection configuration, it allows attackers to exploit the system. Attackers can submit malicious requests that lead to unauthorized FTP mounts being established in a victim's session, enabling them to execute operations on an attacker-controlled FTP server without proper authorization. This flaw is a significant risk for users who have not updated to the patched version.

Affected Version(s)

elFinder < 2.1.70

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.