CVE WATCH / VULNERABILITY DETAIL
CVE-2026-88396
UNKNOWNCVSS 0NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102779
- CVE-2026-102777
- CVE-2026-102282 HIGH 7.1
- CVE-2026-88393
- CVE-2026-105329 MEDIUM 6.3
- CVE-2026-105397 MEDIUM 5.4
- CVE-2026-104890 HIGH 7.2
- CVE-2026-102426
- CVE-2026-102428
- CVE-2026-102775