Description
ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory public/upload/Ymd/. Any logged-in admin user can upload a .php file and reach it directly over HTTP, achieving remote code execution on the server.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Fix
AI Analysis

Impact

ApiAdmin versions 5.0 and prior permit any logged‑in administrator to upload executable files to the web‑accessible directory public/upload/Ymd/ because the upload handler accepts the file extension verbatim and performs no validation or content checking. The uploaded file is then delivered by the web server, allowing an attacker to place a PHP file that can be executed directly over HTTP. This flaw relies on improper input handling and lack of file type restrictions, enabling an attacker with administrative login to run arbitrary code on the server, compromising confidentiality, integrity, and availability of the system.

Affected Systems

The vulnerability affects the ApiAdmin software, specifically all releases version 5.0 and earlier. No specific vendor or additional product variants are named, and version details beyond the upper bound are not provided.

Risk and Exploitability

The CVSS score is not supplied, and the EPSS metric is unavailable; the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw presents a high‑risk remote code execution vector for any authenticated administrator who can upload a file. The lack of chunking or restrictions means exploitation can be performed locally by the admin or remotely if the vulnerability is exposed to an attacker capable of performing admin authentication, without additional conditions noted in the description.

Generated by OpenCVE AI on October 5, 2026 at 17:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict the file upload endpoint to accept only safe MIME types and file extensions, rejecting PHP and other executable files.
  • Store uploaded files in a directory that is not web‑accessible, or configure the web server to block execution of files in public/upload/Ymd/.
  • Apply any vendor‑released patch or upgrade to the latest version of ApiAdmin when available.

Generated by OpenCVE AI on October 5, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory public/upload/Ymd/. Any logged-in admin user can upload a .php file and reach it directly over HTTP, achieving remote code execution on the server.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T15:40:41.964Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T16:17:17.080

Modified: 2026-10-05T16:17:17.080

Link: CVE-2026-88396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T17:30:11Z

Weaknesses

No weakness.