CVE-2026-11621 MEDIUM

CVE-2026-11621: Dcat-Admin User Setting upload editorMDUpload unrestricted upload

Vendor N/A
Product Dcat-Admin
Weakness CWE-434 · Unrestricted file upload
Published June 9, 2026
Last update June 9, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument editormd-image-file causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Key dates

02Disclosure timeline

June 9, 2026 CVE published
June 9, 2026 Record updated