CVE-2026-19383: saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shellexec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product is published by multiple vendors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19383?
The severity of CVE-2026-19383 is classified as medium with a score of 4.7.
How do I fix CVE-2026-19383?
To fix CVE-2026-19383, update the saithink/saigroup SaiAdmin Plugin to version 5.0.2 or later to mitigate the vulnerability.
What type of vulnerability is CVE-2026-19383?
CVE-2026-19383 is categorized as a Malicious File Upload vulnerability.
Is remote exploitation possible with CVE-2026-19383?
Yes, remote exploitation of CVE-2026-19383 is possible due to the unrestricted file upload.
What component is affected by CVE-2026-19383?
The affected component by CVE-2026-19383 is the Plugin Upload Endpoint in the saithink/saigroup SaiAdmin.