9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.
AI Analysis
Unauthenticated attacker can download, delete, or upload files via 'Attachments.aspx' endpoint
Basic Information
ID
CVE-2026-22234
Source
cisa-cg
Published
Jan 8, 2026 at 17:12
Affected Product
Vendor
OPEXUS
Product
eCase Portal
Affected Versions
OPEXUS eCase Portal 0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
OPEXUS
Product
eCasePortal
Version
< 9.0.45.0