CVE-2026-80235: Thinking Software Technology|EFence - Arbitrary File Upload
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EFenceto a version that resolves this vulnerability.Fixed in 1.2.67 - Upgrade
Upgrade
EFenceto a version that resolves this vulnerability.Patch DB Ver:57 or later
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker who can reach the affected EFence service may exploit it. No credentials or user interaction are required.
What is the likely impact of successful exploitation?
An attacker can upload and execute a web shell backdoor, resulting in arbitrary code execution on the EFence server. This can compromise the confidentiality, integrity, and availability of the affected system.