PT-2026-106007 · Undefined · Undefined

CVE-2026-88396

·

Published

2026-10-05

·

Updated

2026-10-05

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move uploaded file() drops the file into the web-accessible directory public/upload/Ymd/. Any logged-in admin user can upload a .php file and reach it directly over HTTP, achieving remote code execution on the server.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-88396

Affected Products

Undefined