CVE-2026-50894: Easyadmin vulnerability
Published Sep 4, 2026
·Updated
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
Affected Software
1 affected component
easyadmin=2.0.2.2
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be authenticated and able to access the background management interface. The issue is remotely exploitable by such users.
2
What is the potential impact of successful exploitation?
A successful attacker can upload a crafted dangerous file, execute arbitrary code on the server, and gain server privileges.