Sceawere

Vulnerability Detail

CVE-2026-19376UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Uasoft Badaso File API Permission Issue

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
Uasoft
Product
Badaso
Attack Type
Permission Issues
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-10T00:17:10.847Z",
  "pubdate": "2026-08-10T00:17:10.847Z",
  "executiveSummary": "A permission-related vulnerability has been identified within the File API component of Uasoft Badaso version 3.0.0-alpha. The security flaw specifically resides in the ApiRequest::class handler located within the src/Routes/api.php file. This vulnerability introduces severe authorization bypass risks, enabling remote threat actors to manipulate API requests and interact with restricted functionalities without proper access validation. The issue stems from inadequate enforcement of access controls within the routing and request handling logic of the affected component. Consequently, unauthorized entities may leverage this flaw to compromise the integrity and confidentiality of sensitive file management operations managed by the application. The risk implications are heightened due to the public disclosure of a functional exploit, allowing malicious actors to actively probe and abuse vulnerable installations. Furthermore, the vendor has not yet responded to early notifications regarding the security issue, leaving deployed instances exposed to potential exploitation in the absence of an official vendor patch. Remediation currently relies on manual hardening and access control enforcement at the application layer.",
  "technicalDetails": "The vulnerability is rooted in flawed access control and authorization mechanisms implemented within the File API component of Uasoft Badaso 3.0.0-alpha. Specifically, the function ApiRequest::class defined in src/Routes/api.php fails to properly validate the privileges and authorization context of incoming API requests before processing them. This architectural oversight allows remote attackers to bypass intended security boundaries and interact directly with sensitive backend endpoints dedicated to file handling and management.\nExploitation of this vulnerability is network-based and can be initiated remotely without requiring prior authentication or elevated privileges, assuming the affected API routes are reachable by the attacker. The attack flow commences with the malicious actor crafting specialized HTTP requests targeting the vulnerable routes managed by ApiRequest::class. Because the application logic fails to adequately verify whether the issuing session possesses the necessary administrative or operational permissions, the request is processed as if it originated from an authorized user.\nUpon successful manipulation of the request parameters, the underlying file API executes the requested operations, potentially leading to unauthorized data exposure, file manipulation, or administrative function execution. The lack of strict middleware checks or role-based access control (RBAC) validation within the routing definition facilitates this bypass. Since the vulnerability is tied to the request handling lifecycle of the API routes, any remote user capable of communicating with the target instance can potentially trigger the vulnerable code path.\nPost-exploitation impact depends on the specific capabilities exposed by the File API component, but generally includes unauthorized access to stored assets, data exfiltration, or further compromise of the application environment. Given that the exploit details are publicly available, automated exploitation scripts can easily target the src/Routes/api.php endpoints across exposed Uasoft Badaso 3.0.0-alpha deployments."
}
CVE-2026-19376: Uasoft Badaso File API Permission Issue (HIGH Severity, CVSS: 7.3) - Sceawere