CVE-2026-71620: Zhao-github ApiAdmin vulnerability
Published Sep 4, 2026
·Updated
File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file
Affected Software
1 affected component
Zhao-github ApiAdmin=5.0.1
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments should be prioritized for investigation?
Deployments running Zhao-github ApiAdmin version 5.0.1 should be prioritized. The available data does not identify whether other versions are affected.
2
What does exploitation involve?
An attacker remotely uploads a crafted .php file and can execute arbitrary code. The available data does not state whether authentication or any specific upload permissions are required.