<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Badaso (3.0.0-Alpha) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/badaso-3.0.0-alpha/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 10 Aug 2026 01:49:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/badaso-3.0.0-alpha/feed.xml" rel="self" type="application/rss+xml"/><item><title>Remote Permission Bypass in Uasoft Badaso File API</title><link>https://feed.craftedsignal.io/briefs/2026-08-10-badaso-permission-bypass/</link><pubDate>Mon, 10 Aug 2026 01:49:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-10-badaso-permission-bypass/</guid><description>A publicly disclosed vulnerability in Uasoft Badaso 3.0.0-alpha allows remote attackers to bypass permission controls within the File API component.</description><content:encoded><![CDATA[<p>A vulnerability (CVE-2026-19376) has been identified in Uasoft Badaso version 3.0.0-alpha, specifically affecting the ApiRequest class located in src/Routes/api.php within the File API component. This vulnerability stems from improper permission handling, which can be triggered remotely by an unauthenticated attacker. The flaw has been publicly disclosed, and the project maintainers have not yet provided a patch or formal response to the reported issue. Given the public availability of the vulnerability details and the lack of a fix, defenders should monitor for unauthorized access attempts directed at the File API endpoints.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to manipulate requests to the File API, leading to a bypass of intended permission controls. This can result in unauthorized access to sensitive files or administrative functions governed by the File API. As of the current reporting, no remediation is available from the vendor, placing all deployments of Badaso 3.0.0-alpha at risk of unauthorized access.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform an inventory of all internet-facing instances of Uasoft Badaso to identify version 3.0.0-alpha.</li>
<li>Implement restrictive access controls at the network perimeter (WAF or firewall) for all traffic targeting API endpoints associated with Badaso's File API until a vendor patch is released.</li>
<li>Audit web server access logs for anomalous POST or GET requests to the File API routes identified in the vulnerability report.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>