A vulnerability was found in saithink/saigroup SaiAdmin up to 5.0.1. It has been rated as critical. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload.

This vulnerability is referenced as CVE-2026-19383. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

This product is published by multiple vendors.