File Upload Vulnerability in ContiNew Admin by ContiNew
CVE-2026-80050

7.1HIGH

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-80050?

ContiNew Admin has a security flaw that allows authenticated users to bypass file-upload permission checks and the file-type allowlist on multipart upload endpoints. This vulnerability permits the uploading of files with arbitrary extensions, enabling attackers to perform chunked uploads, send file parts, and ultimately store unrestricted files in the backend. These files may then be accessed through web server URLs, posing significant risks to data integrity and system security.

Affected Version(s)

continew-admin 0 <= 4.1.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.