PT-2026-81485 · Unknown · Continew Admin

·

CVE-2026-80050

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ContiNew Admin (affected versions not specified)
Description Authenticated users can store files with arbitrary extensions because the software fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints. This allows attackers to initialize chunked uploads, send file parts, and complete the process to leave arbitrary files in the storage backend, which are then accessible via web server URLs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80050

Affected Products

Continew Admin