CVE-2026-108706 | elunez eladmin downloadS3Storage handler /api/s3Storage/download id improper authorization (55fbf70)
A vulnerability was found in elunez eladmin and classified as problematic. Impacted is the function downloadS3Storage of the file /api/s3Storage/download of the component downloadS3Storage handler. Executing a manipulation of the argument ID can lead to improper authorization.
This vulnerability is handled as CVE-2026-108706. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More