What is CVE-2026-49819?
CVE-2026-49819: A missing-authentication / privilege-escalation chain in UpSnap's `POST /api/upsnap/init-superuser` endpoint. Versions 4.4.1 through 5.3.5 are affected, potentially allowing unauthorized admin access. Immediate update to the latest patched version is recommended.
Azərbaycanca: CVE-2026-49819: UpSnap tətbiqində autentifikasiya olmaması səbəbindən `POST /api/upsnap/init-superuser` endpoint-i vasitəsilə imtiyaz artırma zəifliyi. 4.4.1-dən 5.3.5-ə qədər versiyalar təsirlənir; administrator hüquqlarının ələ keçirilməsinə səbəb ola bilər. Təcili olaraq son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of UpSnap are affected by CVE-2026-49819?
This vulnerability affects UpSnap versions 4.4.1 through 5.3.5.
How can I protect against CVE-2026-49819?
It is recommended to immediately update UpSnap to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.