Description
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
Published: 2026-09-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An authenticated remote attacker can exploit a flaw in EasyAdmin v2.0.2.2 that permits unrestricted upload of files with dangerous types. This weakness is defined as CWE-434: Unrestricted Upload of File with Dangerous Type, which allows an attacker to execute arbitrary code on the server with elevated privileges. By uploading a crafted file through the background management interface, the attacker gains execution of arbitrary code, compromising confidentiality, integrity and availability of the system.

Affected Systems

The vulnerability affects only the EasyAdmin package version 2.0.2.2. No specific vendor names are provided, but administrators running EasyAdmin with the background management interface should verify the installed version.

Risk and Exploitability

The flaw is classified as a Remote Code Execution vulnerability with a CVSS score of 9.8, indicating critical severity. The EPSS score is < 1%, suggesting a very low but non-zero exploitation probability. The attack requires valid authenticated credentials to the background management interface, indicating it is not an unauthenticated remote attack. The lack of a KEV listing further implies limited exploitation activity to date. Nevertheless, given the high impact of arbitrary code execution, the risk remains elevated until the vulnerability is remediated.

Generated by OpenCVE AI on September 10, 2026 at 03:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade EasyAdmin to the latest version that addresses the unrestricted file upload issue.
  • Configure strict file type validation in the upload settings to block dangerous file extensions.
  • Disable or restrict access to the background management interface for non‑essential users.
  • Ensure the web server and application run with the least privileges necessary to operate.
  • Apply additional security controls such as file sandboxing and change‑control policies for uploaded content.

Generated by OpenCVE AI on September 10, 2026 at 03:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload in EasyAdmin v2.0.2.2 Leading to Remote Code Execution

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Zhongshaofa
Zhongshaofa easyadmin
Vendors & Products Zhongshaofa
Zhongshaofa easyadmin

Fri, 04 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload in EasyAdmin v2.0.2.2 Leading to Remote Code Execution
Weaknesses CWE-434

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
References

Subscriptions

Zhongshaofa Easyadmin
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T19:21:26.822Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50894

cve-icon Vulnrichment

Updated: 2026-09-09T19:20:44.775Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T21:17:25.177

Modified: 2026-09-09T20:18:05.577

Link: CVE-2026-50894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:00:06Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type