CVE-2026-22235: OPEXUS eComplaint IDOR
Published Jan 8, 2026
·Updated
OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.
Affected Software
2 affected components
OPEXUS eComplaint<9.0.45.0
Opexustech Ecase Ecomplaint<9.0.45.0
Event History
Jan 8, 2026
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22235?
CVE-2026-22235 is considered a high severity vulnerability due to unauthorized file downloading capabilities.
2
How do I fix CVE-2026-22235?
To mitigate CVE-2026-22235, update OPEXUS eComplaint to version 9.0.45.0 or later.
3
What impact does CVE-2026-22235 have on my system?
CVE-2026-22235 allows attackers to access and download files from the system, leading to potential data breaches.
4
Are there any workarounds for CVE-2026-22235?
Temporary workarounds include restricting access to the 'DocumentOpen.aspx' endpoint until the software is updated.
5
Which versions of OPEXUS eComplaint are affected by CVE-2026-22235?
Versions of OPEXUS eComplaint prior to 9.0.45.0 are affected by CVE-2026-22235.