SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-81892

HIGH · CVSS 8.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

EasyAdmin versions 4.0.0 to 4.29.16 and 5.5.1 are vulnerable due to improper validation of the routeName query parameter, allowing low-privilege backend users to bypass path-based access controls and execute unauthorized controllers. This vulnerability poses a high risk to applications using EasyAdmin, particularly those relying solely on path-based protections for sensitive routes. Organizations utilizing affected versions should prioritize upgrading to the patched releases (4.29.16 and 5.5.1) to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81892
Severity
HIGH
CVSS
8.1
EPSS
0.25%

Original NVD Description

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL, and the routeName value was not validated. As a result, a path-based access_control rule protecting the target route was never evaluated, so a low-privilege backend user who can reach a single EasyAdmin URL and knows a target route's name can execute that route's controller, bypassing the path-based rule. Only path-based protections are bypassed. Routes whose controller enforces its own authorization with #[IsGranted] or denyAccessUnlessGranted() remain protected because those checks are recomputed against the swapped-in controller. This issue is fixed in versions 4.29.16 and 5.5.1.