Ghostwire

CVE-2026-108688: Eladmin through 2.7 contains a missing authorization vulnerability in the LocalStorageController uploadPicture handler...

MEDIUM CVSS 4.3 Exploit Available

Published: October 11, 2026 | Last Modified: October 11, 2026

Description

Eladmin through 2.7 contains a missing authorization vulnerability in the LocalStorageController uploadPicture handler that allows low-privileged authenticated users to bypass the storage:add permission. Attackers can send POST requests with image-named files to /api/localStorage/pictures to write files into server local storage and disclose absolute server paths.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References