What is CVE-2026-19376?
A permission vulnerability has been discovered in Uasoft Badaso 3.0.0-alpha within the `ApiRequest::class` function located in `src/Routes/api.php`. This flaw allows remote exploitation, leading to authorization issues in the File API component. Since an exploit has been publicly disclosed, immediate security patching is recommended.
Azərbaycanca: Uasoft Badaso 3.0.0-alpha versiyasında `src/Routes/api.php` faylındakı `ApiRequest::class` funksiyasında icazə zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücuma imkan yaradaraq fayl API komponentində səlahiyyət problemlərinə səbəb olur. İstismar kodunun ictimaiyyətə açıq olduğu bildirilir, dərhal təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which version of Uasoft Badaso is affected by CVE-2026-19376?
This vulnerability affects Uasoft Badaso version 3.0.0-alpha.
Is there a publicly available exploit for CVE-2026-19376?
Yes, the exploit code has been publicly disclosed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.