Description
A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manipulation of the argument uploadPath causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Product status
2.1
2.2
2.3
2.4
2.5
2.6
2.7
Timeline
| 2026-06-01: | Advisory disclosed |
| 2026-06-01: | VulDB entry created |
| 2026-06-01: | VulDB entry last update |
Credits
Ana10gy (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/367646 (VDB-367646 | elunez eladmin Application Deployment App.java command injection)
vuldb.com/vuln/367646/cti (VDB-367646 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10550 (CVE-2026-10550 | CVE Analysis and Report)
vuldb.com/submit/828507 (Submit #828507 | elunez eladmin <= v2.7 (2026.04.21) Command Injection)
github.com/elunez/eladmin/issues/899
github.com/elunez/eladmin/