CVE-2026-19376

7.3

Uasoft · Badaso

Uasoft Badaso version 3.0.0-alpha is affected by a permission and privilege assignment vulnerability, enabling unauthenticated remote attackers to bypass security controls.

Executive summary

A high-severity privilege assignment vulnerability in Uasoft Badaso allows unauthenticated attackers to bypass security controls and potentially gain unauthorized access to administrative functions.

Vulnerability

The application contains flaws in privilege management (CWE-275, CWE-266), which permit an unauthenticated remote attacker to manipulate access controls and gain elevated privileges.

Business impact

With a CVSS score of 7.3, this vulnerability represents a severe risk to application security. An attacker could exploit this flaw to gain unauthorized administrative access, resulting in the compromise of sensitive data, unauthorized modification of system settings, or the total takeover of the Badaso instance.

Remediation

Immediate Action: Check the official Uasoft Badaso repository for security patches and upgrade the installation to a version that addresses these privilege management flaws.

Proactive Monitoring: Audit user account creation logs and monitor for unauthorized administrative actions or unexpected changes to role-based access control configurations.

Compensating Controls: Implement strict network-level access controls to limit exposure of the application to untrusted networks and utilize a WAF to filter suspicious requests targeting administrative endpoints.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Security teams should treat this vulnerability with high urgency. Because it allows for unauthorized privilege escalation without authentication, it is imperative to apply available updates or restrict external access to the affected instance until a fix is deployed.