Unrestricted Upload Vulnerability in SaiAdmin Plugin by Saithink
CVE-2026-19383
Key Information:
Badges
What is CVE-2026-19383?
A vulnerability exists in the SaiAdmin by Saithink, impacting versions up to 5.0.1. The flaw enables unrestricted file uploads through the 'shell_exec' function located in the Plugin Upload Endpoint. This security gap allows for potential remote code execution, posing significant risks as it can be exploited by unauthorized individuals. Public knowledge of the exploit further exacerbates the threat landscape, making it crucial for users to address this vulnerability promptly.
Affected Version(s)
SaiAdmin 5.0.0
SaiAdmin 5.0.1
SaiAdmin 5.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
