CVE-2026-82915: Path Traversal in Bimser Solution Software's eBA Plus
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal.
This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bimser Solution Software eBA Plus Document and Workflow Management Systemto a version that resolves this vulnerability.Fixed in 10.0.11
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects Bimser Solution Software eBA Plus Document and Workflow Management System versions from 6.7.141 before 10.0.11. Deployments running version 10.0.11 or later are not identified as affected by the supplied information.
What level of access does an attacker need?
Exploitation requires low-level privileges (PR:L) and can be performed remotely over the network (AV:N). No user interaction is required (UI:N).
What is the likely impact of successful exploitation?
The provided vector indicates high confidentiality impact (C:H), with no integrity or availability impact indicated (I:N/A:N). This is consistent with unauthorized access to files through path traversal.