CVE-2026-19383 MEDIUM

CVE-2026-19383: saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload

Vendor Saithink
Product SaiAdmin
Weakness CWE-434 · Unrestricted file upload
Published August 10, 2026
Last update August 10, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product is published by multiple vendors.

Key dates

02Disclosure timeline

August 10, 2026 CVE published

Related vulnerabilities

04Related CVE