SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-50894

CRITICAL · CVSS 9.8 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

EasyAdmin version 2.0.2.2 is susceptible to an unrestricted file upload vulnerability in its background management interface, enabling authenticated remote attackers to upload malicious files. This flaw can lead to arbitrary code execution and potential server compromise. Organizations using this version should prioritize patching to mitigate the risk of unauthorized access and control over their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50894
Severity
CRITICAL
CVSS
9.8
EPSS
0.48%

Original NVD Description

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.