Vulnerability Description
Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/pyuysig/50dc365f54f95396bb67532f02b34bb0
- https://gist.github.com/pyuysig/50dc365f54f95396bb67532f02b34bb0
FAQ
What is CVE-2026-50891?
CVE-2026-50891 is a vulnerability with a CVSS score of 8.1 (HIGH). Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.
How severe is CVE-2026-50891?
CVE-2026-50891 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50891?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.