CVE-2026-32867

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. Uploading a large number of files could consume storage.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opexustech:ecase_ecomplaint:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-19 16:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32867

Mitre link : CVE-2026-32867

CVE.ORG link : CVE-2026-32867


JSON object : View

Products Affected

opexustech

  • ecase_ecomplaint
CWE
CWE-425

Direct Request ('Forced Browsing')

CWE-639

Authorization Bypass Through User-Controlled Key