Vulnerability Details CVE-2026-2978
A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the component Scheduled Task API. Performing a manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 9.6%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 6.5
Products affected by CVE-2026-2978
-
cpe:2.3:a:fastapiadmin:fastapi-admin:2.0
-
cpe:2.3:a:fastapiadmin:fastapi-admin:2.1
-
cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0