Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108688

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 11, 2026
Vendor unknown

Description

Eladmin through 2.7 contains a missing authorization vulnerability in the LocalStorageController uploadPicture handler that allows low-privileged authenticated users to bypass the storage:add permission. Attackers can send POST requests with image-named files to /api/localStorage/pictures to write files into server local storage and disclose absolute server paths.

References