{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/uasoft/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19376"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Badaso (3.0.0-alpha)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Uasoft"],"content_html":"\u003cp\u003eA vulnerability (CVE-2026-19376) has been identified in Uasoft Badaso version 3.0.0-alpha, specifically affecting the ApiRequest class located in src/Routes/api.php within the File API component. This vulnerability stems from improper permission handling, which can be triggered remotely by an unauthenticated attacker. The flaw has been publicly disclosed, and the project maintainers have not yet provided a patch or formal response to the reported issue. Given the public availability of the vulnerability details and the lack of a fix, defenders should monitor for unauthorized access attempts directed at the File API endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to manipulate requests to the File API, leading to a bypass of intended permission controls. This can result in unauthorized access to sensitive files or administrative functions governed by the File API. As of the current reporting, no remediation is available from the vendor, placing all deployments of Badaso 3.0.0-alpha at risk of unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of all internet-facing instances of Uasoft Badaso to identify version 3.0.0-alpha.\u003c/li\u003e\n\u003cli\u003eImplement restrictive access controls at the network perimeter (WAF or firewall) for all traffic targeting API endpoints associated with Badaso's File API until a vendor patch is released.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST or GET requests to the File API routes identified in the vulnerability report.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T01:49:42Z","date_published":"2026-08-10T01:49:42Z","id":"https://feed.craftedsignal.io/briefs/2026-08-10-badaso-permission-bypass/","summary":"A publicly disclosed vulnerability in Uasoft Badaso 3.0.0-alpha allows remote attackers to bypass permission controls within the File API component.","title":"Remote Permission Bypass in Uasoft Badaso File API","url":"https://feed.craftedsignal.io/briefs/2026-08-10-badaso-permission-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Uasoft","version":"https://jsonfeed.org/version/1.1"}