CVE-2026-75413: DocSys vulnerability
Published Aug 26, 2026
·Updated
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
Affected Software
1 affected component
DocSys=2.02.80
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit the downloadDocEx.do interface; no login is required.
2
What does an attacker need to provide?
The attacker needs to send a request to downloadDocEx.do with a targetPath parameter identifying the file to download.
3
How can I determine whether my deployment is affected?
A deployment is affected if it runs DocSys V2.02.80 and exposes the unauthenticated downloadDocEx.do interface that accepts the targetPath parameter.