PatchSiren

1024‑lab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH 1024‑lab CVE published 2026-09-15

CVE-2026-88619

CVE-2026-88619 is a missing authorization vulnerability in 1024-lab SmartAdmin v3.30.0's scheduled-job management module. The AdminSmartJobController exposes endpoints without method-level permission checks, allowing low-privileged authenticated users to access administrator-intended functionality. This vulnerability has a high CVSS score of 8.1 and is classified as HIGH severity. Defenders and administra [truncated]

MEDIUM 1024-lab CVE published 2026-09-15

CVE-2026-88618

CVE-2026-88618 is a stored cross-site scripting vulnerability in 1024-lab SmartAdmin v3.30.0's file upload functionality, allowing remote attackers to execute arbitrary code. Defenders should assess exposure, prioritize remediation, and verify vulnerability details through additional testing and review of official advisories. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM, indicating a [truncated]

CRITICAL 1024-lab CVE published 2026-09-15

CVE-2026-88617

CVE-2026-88617 SmartAdmin v3.30.0 authorization flaw allows remote privilege escalation through the configuration query endpoint. Defenders and administrators should assess exposure, prioritize verification, and review configuration for potential vulnerabilities. This flaw could lead to unauthorized access and control, emphasizing the need for immediate attention and mitigation. Assess exposure, prioritiz [truncated]