easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
History

Thu, 10 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload in EasyAdmin v2.0.2.2 Leading to Remote Code Execution

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Zhongshaofa
Zhongshaofa easyadmin
Vendors & Products Zhongshaofa
Zhongshaofa easyadmin

Fri, 04 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload in EasyAdmin v2.0.2.2 Leading to Remote Code Execution
Weaknesses CWE-434

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-09-04T00:00:00.000Z

Updated: 2026-09-09T19:21:26.822Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50894

cve-icon Vulnrichment

Updated: 2026-09-09T19:20:44.775Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T21:17:25.177

Modified: 2026-09-09T20:18:05.577

Link: CVE-2026-50894

cve-icon Redhat

No data.