Skip to content
Threat Feed
high advisory

Remote Permission Bypass in Uasoft Badaso File API

A publicly disclosed vulnerability in Uasoft Badaso 3.0.0-alpha allows remote attackers to bypass permission controls within the File API component.

A vulnerability (CVE-2026-19376) has been identified in Uasoft Badaso version 3.0.0-alpha, specifically affecting the ApiRequest class located in src/Routes/api.php within the File API component. This vulnerability stems from improper permission handling, which can be triggered remotely by an unauthenticated attacker. The flaw has been publicly disclosed, and the project maintainers have not yet provided a patch or formal response to the reported issue. Given the public availability of the vulnerability details and the lack of a fix, defenders should monitor for unauthorized access attempts directed at the File API endpoints.

Impact

Successful exploitation allows remote attackers to manipulate requests to the File API, leading to a bypass of intended permission controls. This can result in unauthorized access to sensitive files or administrative functions governed by the File API. As of the current reporting, no remediation is available from the vendor, placing all deployments of Badaso 3.0.0-alpha at risk of unauthorized access.

Recommendation

  • Perform an inventory of all internet-facing instances of Uasoft Badaso to identify version 3.0.0-alpha.
  • Implement restrictive access controls at the network perimeter (WAF or firewall) for all traffic targeting API endpoints associated with Badaso's File API until a vendor patch is released.
  • Audit web server access logs for anomalous POST or GET requests to the File API routes identified in the vulnerability report.

Immediate actions

Inventory all internet-facing instances of Uasoft Badaso to identify 3.0.0-alpha deployments.

IT Operations 24h

Mitigations

Restrict access to the Badaso File API routes at the network edge.

immediate IT Operations

CVE-2026-19376