CVE-2026-32867: OPEXUS eComplaint unauthenticated file upload
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. Uploading a large number of files could consume storage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32867?
CVE-2026-32867 is classified as a high severity vulnerability due to the potential for unauthenticated file uploads.
How do I fix CVE-2026-32867?
To fix CVE-2026-32867, upgrade OPEXUS eComplaint to version 10.1.0.0 or later.
Who is affected by CVE-2026-32867?
CVE-2026-32867 affects users of OPEXUS eComplaint versions prior to 10.1.0.0.
What can an attacker do with CVE-2026-32867?
An attacker can exploit CVE-2026-32867 to upload arbitrary files into case portals, potentially disrupting case management.
Is user authentication required to exploit CVE-2026-32867?
No, CVE-2026-32867 can be exploited by unauthenticated attackers.