CVE-2026-50894
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
Published 2026-09-04. Last modified 2026-09-09.