CVE-2026-75339

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.

  • Published Aug 28, 2026
  • CVSS 8.8 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

CVE-2026-75339 at the National Vulnerability Database