Undefined · Undefined · CVE-2026-11621
**Name of the Vulnerable Software and Affected Versions**
Dcat-Admin versions prior to 2.2.3-beta
**Description**
A weakness in the User Setting Page component allows for unrestricted file upload. This occurs when the `editormd-image-file` argument is manipulated within the `editorMDUpload()` function at the '/admin/dcat-api/editor-md/upload' endpoint. The issue can be exploited remotely.
**Recommendations**
Update Dcat-Admin to a version later than 2.2.3-beta.
As a temporary mitigation, restrict access to the '/admin/dcat-api/editor-md/upload' endpoint.