CVE-2026-108706
Received Received - Intake

eladmin Missing Authorization in S3 Storage Download Handler

Vulnerability report for CVE-2026-108706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

eladmin through commit 55fbf70 contains a missing authorization vulnerability in the downloadS3Storage handler that allows any authenticated user to retrieve stored object URLs without storage permissions. Attackers can enumerate sequential ids against GET /api/s3Storage/download/{id} to collect URLs of all uploaded objects, exposing file contents on publicly readable buckets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
elunez eladmin 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization flaw in the eladmin software. It exists in the downloadS3Storage handler where any authenticated user can retrieve stored object URLs without needing storage permissions. Attackers exploit this by sending requests to GET /api/s3Storage/download/{id} and enumerating sequential IDs to collect all uploaded object URLs. If the S3 buckets are publicly readable, this exposes the contents of those files.

Detection Guidance

Check for unauthorized access to the GET /api/s3Storage/download/{id} endpoint by monitoring logs for sequential ID enumeration attempts. Use tools like curl to test the endpoint with different IDs: curl -u username:password http://target/api/s3Storage/download/1. If responses return file URLs without proper authorization, the vulnerability is present.

Impact Analysis

If you use eladmin with S3 storage, an attacker with basic authentication could access files they shouldn't. This could lead to data breaches, exposure of sensitive information, or unauthorized file downloads. The impact depends on what data is stored in the S3 buckets.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection regulations like GDPR and HIPAA. It enables unauthorized access to sensitive data, which could result in data breaches. Organizations using this software may face regulatory penalties, legal consequences, and reputational damage.

Mitigation Strategies

Immediately restrict access to the /api/s3Storage/download/{id} endpoint by implementing proper authorization checks. Ensure only users with storage:list permission can access it. Update the S3StorageController.java to add @PreAuthorize("hasPermission('storage','list')") to the downloadS3Storage method. Verify bucket permissions are not set to public read.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart