CVE-2026-50894 Details
Description
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
A vulnerability in EasyAdmin version 2.0.2.2 allows authenticated remote attackers to upload files with dangerous extensions, such as .php, through the background management interface. This unrestricted file upload can be exploited to execute arbitrary code and gain server privileges. The issue arises from inadequate validation of upload file extensions, enabling attackers to manipulate the application's configuration to accept executable files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/lilil3333/cve/issues/1 | CISA-ADP | ExploitIssue TrackingTechnical Description |
| https://github.com/lilil3333/cve/issues/1 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://github.com/zhongshaofa/easyadmin/ | [email protected] | ProductSource CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| easyadmin | 2.0.2.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion