{"api_version":"1","generated_at":"2026-09-05T03:55:00+00:00","cve":"CVE-2026-50894","urls":{"html":"https://cve.report/CVE-2026-50894","api":"https://cve.report/api/cve/CVE-2026-50894.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-50894","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-50894"},"summary":{"title":"CVE-2026-50894","description":"easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.","state":"PUBLISHED","assigner":"mitre","published_at":"2026-09-04 21:17:25","updated_at":"2026-09-04 21:17:25"},"problem_types":["n/a"],"metrics":[],"references":[{"url":"https://github.com/lilil3333/cve/issues/1","name":"https://github.com/lilil3333/cve/issues/1","refsource":"cve@mitre.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/zhongshaofa/easyadmin/","name":"https://github.com/zhongshaofa/easyadmin/","refsource":"cve@mitre.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-50894","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50894","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2026-09-04T20:12:15.598Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"url":"https://github.com/zhongshaofa/easyadmin/"},{"url":"https://github.com/lilil3333/cve/issues/1"}]}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2026-50894","datePublished":"2026-09-04T00:00:00.000Z","dateReserved":"2026-06-07T00:00:00.000Z","dateUpdated":"2026-09-04T20:12:15.598Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-04 21:17:25","lastModifiedDate":"2026-09-04 21:17:25","problem_types":["n/a"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"50894","Ordinal":"1","Title":"CVE-2026-50894","CVE":"CVE-2026-50894","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"50894","Ordinal":"1","NoteData":"easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.","Type":"Description","Title":"CVE-2026-50894"}]}}}