CVE-2026-88617

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

  • Published Sep 15, 2026
  • CVSS 9.8 critical
  • 0.6% chance of exploitation in the next 30 days (EPSS)

CVE-2026-88617 at the National Vulnerability Database