CVE-2026-50894
Received Received - Intake

Unrestricted File Upload in EasyAdmin Background Interface

Vulnerability report for CVE-2026-50894, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easyadmin easyadmin 2.0.2.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in easyadmin v2.0.2.2 allows authenticated remote attackers to upload dangerous files through the background management interface. This unrestricted file upload can lead to arbitrary code execution and full server privilege takeover.

Detection Guidance

To detect this vulnerability, check for unauthorized file uploads in the easyadmin background management interface. Look for unexpected file types or files in directories where they shouldn't be. Manually inspect uploaded files and verify their integrity. Check server logs for suspicious upload activities or unusual file extensions.

Impact Analysis

If exploited, attackers can gain full control of the server hosting easyadmin. This may result in data theft, system compromise, or further network infiltration. Unauthorized code execution could disrupt services or install malware.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and security. GDPR and HIPAA mandate strict access controls and protection against unauthorized access. A breach could lead to legal penalties and reputational damage.

Mitigation Strategies

Immediately update easyadmin to the latest patched version. If an update is unavailable, restrict file upload functionality to trusted users only. Implement strict file type validation and rename uploaded files to prevent execution of malicious code. Disable unnecessary file upload features if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50894. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart