Description
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-09
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure permission check in the File API of Uasoft Badaso version 3.0.0‑alpha allows attackers to manipulate the ApiRequest::class function in src/Routes/api.php. The flaw can be triggered remotely via crafted requests, enabling an attacker to bypass the intended authorization controls and gain access to or modify protected files. The impact is a privilege escalation that compromises the confidentiality and integrity of the system’s data.

Affected Systems

The vulnerability affects the Uasoft Badaso product, specifically version 3.0.0‑alpha of the File API component. No other versions or other vendors are explicitly listed as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity vulnerability, and the EPSS score is not available, providing no quantitative exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attacker can exploit the flaw remotely by sending crafted API requests to the File API endpoint, exploiting improperly enforced permission checks.

Generated by OpenCVE AI on August 10, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Uasoft Badaso or apply the vendor’s fix that corrects the API permission validation.
  • If no patch is available, enforce strict role‑based access control on the File API endpoints, validating user roles before processing requests.
  • Review and strengthen the application’s authorization logic to ensure that every API call verifies the caller’s privileges against the required permissions, addressing the root causes identified in CWE‑266 and CWE‑275.

Generated by OpenCVE AI on August 10, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Uasoft Badaso File API api.php class permission
First Time appeared Uasoft
Uasoft badaso
Weaknesses CWE-266
CWE-275
CPEs cpe:2.3:a:uasoft:badaso:*:*:*:*:*:*:*:*
Vendors & Products Uasoft
Uasoft badaso
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T23:30:09.475Z

Reserved: 2026-08-09T13:12:01.155Z

Link: CVE-2026-19376

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T00:30:03Z

Weaknesses