MEDIUM
elunez
CVE published 2026-10-11
CVE-2026-108688
CVE-2026-108688 is a missing authorization vulnerability in Eladmin through version 2.7, specifically in the LocalStorageController uploadPicture handler. This allows low-privileged authenticated users to bypass the storage:add permission and write files into server local storage, disclosing absolute server paths. The vulnerability was reported by [email protected] and is documented in the CVE Prog [truncated]