Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22786

24
FAUCET Score

CVE-2026-22786 is a path traversal vulnerability affecting Gin-vue-admin versions up to v2.8.7, specifically within its breakpoint resume upload functionality. An authenticated attacker with file upload privileges can exploit this flaw to upload arbitrary files to any directory on the server due to insufficient validation of the fileName parameter. The vulnerability carries a CVSS v4.0 score of 7.3 (HIGH), indicating a high impact on confidentiality, integrity, and availability, with a low attack complexity. While there is no known active exploitation, public exploit code, or significant community discussion, the vulnerability is easily exploitable by an attacker with the necessary privileges.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.8.7CPE matchmatch criteria
cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.94%
Probability of exploitation in next 30 days
EPSS Percentile
57.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0094 is in the 43rd percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

goGHSA-3558-j79f-vvm6high

Gin-vue-admin has arbitrary file upload vulnerability caused by path traversal

Jan 13, 2026

References

github.com / flipped-aurora/gin-vue-admin/commit/2242f5d6e133e96d1b359ac019bf54fa0e975dd5
Patch
github.com / flipped-aurora/gin-vue-admin/security/advisories/GHSA-3558-j79f-vvm6
ExploitVendor Advisory