Intel

AIKIDO-2026-10519

easycorp/easyadmin-bundle is vulnerable to Authorization Bypass Through User-Controlled Key

Authorization Bypass Through User-Controlled Key Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 23, 2026

82

High Risk

This Affects:

PHPeasycorp/easyadmin-bundle
0.0.1 - 4.29.5
Fixed in 4.29.6
5.0.0 - 5.0.5
Fixed in 5.0.6
Are you affected? Scan for Free

TL;DR

Multiple vulnerabilities in EasyAdminBundle allowed authorization bypass in batch delete actions through attacker-controlled entity class parameters, stored XSS through dangerous URL schemes rendered as clickable links, CSS injection through unsanitized color values, path traversal through unsafe stored upload filenames, and missing permission checks on internal autocomplete/filter endpoints. Successful exploitation could let authenticated users access unauthorized data, delete unintended entities, execute script in admin sessions, or read local files.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

easycorp/easyadmin-bundle is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.1 - 4.29.5 and 5.0.0 - 5.0.5.

How to fix this

Upgrade the easycorp/easyadmin-bundle library to the patch version.