Uasoft · Badaso · CVE-2026-19376
**Name of the Vulnerable Software and Affected Versions**
Uasoft Badaso version 3.0.0-alpha
**Description**
A permission issue exists within the File API component, specifically affecting the `ApiRequest::class` function in the `src/Routes/api.php` file. This flaw allows a remote attacker to manipulate the system and bypass intended permission controls.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict access to the `ApiRequest::class` function within the `src/Routes/api.php` file.