CVE-2026-6835: aEnrich|a+HCM - Arbitrary File Upload
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6835?
The severity of CVE-2026-6835 is considered high due to its potential for arbitrary file uploads and exploitation by unauthenticated attackers.
How do I fix CVE-2026-6835?
To fix CVE-2026-6835, you should implement proper file upload restrictions, validate file types, and ensure authenticated access to file upload functionalities.
What types of files can be uploaded due to CVE-2026-6835?
CVE-2026-6835 allows the upload of arbitrary files, including potentially harmful HTML documents.
What are the potential consequences of CVE-2026-6835?
The consequences of CVE-2026-6835 include unauthorized file uploads that can lead to Cross-Site Scripting (XSS) attacks and further exploitation.
Which software is affected by CVE-2026-6835?
The software affected by CVE-2026-6835 is the aEnrich a+HCM application.