PT-2026-47633 · Undefined · Undefined

·

CVE-2026-11621

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dcat-Admin versions prior to 2.2.3-beta
Description A weakness in the User Setting Page component allows for unrestricted file upload. This occurs when the editormd-image-file argument is manipulated within the editorMDUpload() function at the '/admin/dcat-api/editor-md/upload' endpoint. The issue can be exploited remotely.
Recommendations Update Dcat-Admin to a version later than 2.2.3-beta. As a temporary mitigation, restrict access to the '/admin/dcat-api/editor-md/upload' endpoint.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11621

Affected Products

Undefined