File Upload Vulnerability in ContiNew Admin by ContiNew
CVE-2026-80050
7.1HIGH
What is CVE-2026-80050?
ContiNew Admin has a security flaw that allows authenticated users to bypass file-upload permission checks and the file-type allowlist on multipart upload endpoints. This vulnerability permits the uploading of files with arbitrary extensions, enabling attackers to perform chunked uploads, send file parts, and ultimately store unrestricted files in the backend. These files may then be accessed through web server URLs, posing significant risks to data integrity and system security.
Affected Version(s)
continew-admin 0 <= 4.1.0
