CVE-2026-75339
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.
- Published Aug 28, 2026
- CVSS 8.8 high
- 0.4% chance of exploitation in the next 30 days (EPSS)