Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fastapiadmin:fastapi-admin:2.1:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0:*:*:*:*:*:*:* |
cpe:2.3:a:fastapiadmin:fastapiadmin:*:*:*:*:*:*:*:* |
| Vendors & Products |
Fastapiadmin fastapi-admin
|
Wed, 25 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastapiadmin fastapi-admin
|
|
| CPEs | cpe:2.3:a:fastapiadmin:fastapi-admin:2.0:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.1:*:*:*:*:*:*:* cpe:2.3:a:fastapiadmin:fastapi-admin:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fastapiadmin fastapi-admin
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastapiadmin
Fastapiadmin fastapiadmin |
|
| Vendors & Products |
Fastapiadmin
Fastapiadmin fastapiadmin |
Mon, 23 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the component Scheduled Task API. Performing a manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Title | FastApiAdmin Scheduled Task API controller.py upload_file_controller unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-23T13:15:32.013Z
Reserved: 2026-02-22T15:09:10.914Z
Link: CVE-2026-2978
Updated: 2026-02-23T13:15:25.296Z
Status : Analyzed
Published: 2026-02-23T08:16:13.983
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-2978
No data.
OpenCVE Enrichment
Updated: 2026-04-18T11:15:35Z