Home

Description

An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) via manipulating the func field of scheduled tasks.

PUBLISHED Reserved 2026-04-06 | Published 2026-06-09 | Updated 2026-06-09 | Assigner mitre

References

github.com/...ties/tree/master/fastapi-admin/vulnerability-8 exploit

github.com/...ties/tree/master/fastapi-admin/vulnerability-8

cve.org (CVE-2026-36724)

nvd.nist.gov (CVE-2026-36724)

Download JSON