Vulnerability Description
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument editormd-image-file causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://vuldb.com/cve/CVE-2026-11621
- https://vuldb.com/submit/834849
- https://vuldb.com/vuln/369302
- https://vuldb.com/vuln/369302/cti
- https://www.yuque.com/u25169484/wroc9b/co6eg4x23xkfesng
FAQ
What is CVE-2026-11621?
CVE-2026-11621 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulati...
How severe is CVE-2026-11621?
CVE-2026-11621 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11621?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.