What is CVE-2026-55579?
Pheditor versions 2.0.1 to before 2.0.6 ship with a hardcoded default admin password and lack a forced password change mechanism upon first login, leaving affected PHP-based file managers exposed. Immediate update to version 2.0.6 or higher and changing the default password is strongly recommended.
Azərbaycanca: Pheditor 2.0.1-dən 2.0.6-ya qədər olan versiyalarda standart "admin" parolu hardcoded olaraq qalır və ilk girişdə parol dəyişməyə məcbur edilmir. Bu zəiflik təsirlənmiş PHP əsaslı fayl menecerlərini sızdırma riski yaradır. Dərhal 2.0.6 versiyasına yenilənməli və parol dəyişdirilməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of the Pheditor file manager are affected by the default admin password vulnerability?
The vulnerability affects Pheditor versions 2.0.1 to before 2.0.6.
What measures should be taken to mitigate CVE-2026-55579?
Immediate update to version 2.0.6 or higher and changing the default password is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.