CVE-2026-2976

MEDIUM

FastApiAdmin <2.2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Download Endpoint. This manipulation of the argument file_path causes information disclosure. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-284 CWE-434
Status published
Products (4)
fastapiadmin/fastapi-admin 2.0
fastapiadmin/fastapi-admin 2.1
fastapiadmin/fastapi-admin 2.2.0
fastapiadmin/fastapiadmin < 2.2.0
Published Feb 23, 2026
Tracked Since Feb 23, 2026