A vulnerability, which was classified as critical, has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function
ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2026-19376. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.