Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6496

20
FAUCET Score

A path traversal vulnerability exists in TinyFileManager versions up to 2.6, specifically in the POST Parameter Handler function of /filemanager.php. An authenticated attacker can manipulate the file[] argument to traverse directory structures and access unauthorized files on the affected system. This vulnerability affects organizations deploying this open-source file management application. The vulnerability has a CVSS 3.1 score of 5.4 (Medium severity) with a network-based attack vector requiring low complexity and valid user credentials. While the vulnerability does not compromise confidentiality, it enables integrity compromise and availability disruption through unauthorized file access and manipulation. The FAUCET Risk Score of 32.0/100 indicates moderate concern. Exploitation status is elevated due to public disclosure of the vulnerability and available proof-of-concept code, though formal CISA KEV listing has not been assigned. The vendor declined to engage during responsible disclosure efforts. Active community attention combined with public exploit availability suggests this vulnerability warrants prompt patching in any TinyFileManager deployments that cannot be immediately decommissioned or segmented from production environments.

Impacted Technologies

VendorProductVersion(s)CPE
PrasathmaniTinyFileManager
2.0, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 47th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

drive.google.com / file/d/14taA8w3e5z3gl4WttpB4_CquwQdz1i6r/view
vuldb.com / submit/787942
vuldb.com / vuln/358039
vuldb.com / vuln/358039/cti