OVERVIEW: CVE-2026-6497 is a server-side request forgery (SSRF) vulnerability affecting TinyFileManager versions up to 2.6. The flaw exists in the file upload handler component (/filemanager.php) where manipulation of the uploadurl parameter allows attackers to initiate unauthorized server-side requests. This widely-deployed file management application is exposed to remote exploitation without requiring administrative privileges. SEVERITY: The vulnerability carries a CVSS v3.1 score of 6.3 (Medium) with a network-based attack vector requiring low complexity and low privileges. The impact is moderate, affecting confidentiality, integrity, and availability equally. While not rated as critical, the SSRF nature of this flaw could enable attackers to access internal systems, exfiltrate data, or pivot to other network resources depending on server configuration and network segmentation. EXPLOITATION STATUS: The vulnerability has been publicly disclosed with exploit code available in the wild. The vulnerability is currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as actively exploited in the wild, though EPSS scoring suggests relatively low predictive exploitation likelihood. The vendor has not responded to coordinated disclosure efforts, indicating no patch is forthcoming, leaving affected organizations dependent on compensating controls or alternative solutions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Prasathmani | TinyFileManager | 2.0, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.