CVE-2026-6496 | prasathmani TinyFileManager up to 2.6 POST Parameter /filemanager.php file[] path traversal
A vulnerability, which was classified as critical, was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal.
This vulnerability was named CVE-2026-6496. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.