CVE WATCH / VULNERABILITY DETAIL

CVE-2026-88396

UNKNOWNCVSS 0NVD feed

Published 5 October 2026 · tracked since 5 October 2026

Description

ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-88396 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-88396

UNKNOWNCVSS 0NVD feed

Published 5 October 2026 · tracked since 5 October 2026

Description

ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]