---
id: CVE-2026-19376
title: A vulnerability has been found in Uasoft Badaso 3.0.0-alpha
summary: >-
  A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This
  vulnerability affects the function ApiRequest::class of the file
  src/Routes/api.php of the component File API. The manipulation leads to
  permission issues. It is possible …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-275
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19376'
references:
  - url: 'https://github.com/uasoft-indonesia/badaso/issues/1100'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-19376'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/866302'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387270'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387270/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-10T05:39:02.155Z'
epss: 0.00472
epssPercentile: 0.38137
---

## Overview

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
