PT-2026-106007 · Undefined · Undefined
CVE-2026-88396
·
Published
2026-10-05
·
Updated
2026-10-05
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move uploaded file() drops the file into the web-accessible directory public/upload/Ymd/. Any logged-in admin user can upload a .php file and reach it directly over HTTP, achieving remote code execution on the server.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined