---
id: CVE-2026-53769
title: Avo is a framework to create admin panels for Ruby on Rails apps
summary: >-
  Avo is a framework to create admin panels for Ruby on Rails apps. From version
  2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks
  server-side upload authorization and bypasses the documented field-level
  upload…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
  - CWE-863
  - CWE-639
vendor: avo-hq
product: avo
affected:
  - 'avo >= 2.28.0, < 3.32.0'
patched:
  - avo 3.32.0
published: '2026-09-04'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:17:03.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53769'
references:
  - url: >-
      https://github.com/avo-hq/avo/commit/de12070dbac0cb6a7e2bea357f9697f99e92554c
    label: security-advisories@github.com
  - url: 'https://github.com/avo-hq/avo/pull/4520'
    label: security-advisories@github.com
  - url: 'https://github.com/avo-hq/avo/releases/tag/v3.32.0'
    label: security-advisories@github.com
  - url: 'https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9'
    label: security-advisories@github.com
  - url: 'https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53769.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-53769'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2528883'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-53769'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53769'
  - url: 'https://github.com/advisories/GHSA-pqpw-cvm4-8mv9'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - ghsa
  - rubygems
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T15:57:19.419562Z'
epss: 0.00423
epssPercentile: 0.33869
aliases:
  - GHSA-pqpw-cvm4-8mv9
ecosystem: rubygems
ingestedAt: '2026-07-09T21:52:34.710Z'
---

## Overview

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-53769)

Affected packages:

- `avo >= 2.28.0, < 3.32.0`

Patched in:

- `avo 3.32.0`

Source: https://github.com/advisories/GHSA-pqpw-cvm4-8mv9

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift GitOps, Red Hat OpenStack Platform 18.0 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift GitOps, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53769.json)
