---
id: CVE-2026-50894
title: >-
  easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous
  Type in the background management interface which allows authenticated remote
  attackers to execute arbitrary code and gain server privileges via a crafted
  fil…
summary: >-
  easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous
  Type in the background management interface which allows authenticated remote
  attackers to execute arbitrary code and gain server privileges via a crafted
  fil…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2026-09-04'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:18:05.577'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50894'
references:
  - url: 'https://github.com/lilil3333/cve/issues/1'
    label: cve@mitre.org
  - url: 'https://github.com/zhongshaofa/easyadmin/'
    label: cve@mitre.org
  - url: 'https://github.com/lilil3333/cve/issues/1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00476
epssPercentile: 0.40317
ingestedAt: '2026-09-08T20:10:03.168Z'
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-09T19:21:03.554926Z'
---

## Overview

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
