CVE-2026-85134: Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server.
This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bimser eBA Plus Document and Workflow Management Systemto a version that resolves this vulnerability.Fixed in 10.0.11
Event History
Frequently Asked Questions
Which deployments are affected?
Bimser eBA Plus Document and Workflow Management System versions from 6.7.141 before 10.0.11 are affected.
What access does an attacker need to exploit this issue?
The vulnerability is network-accessible and requires low-level privileges. No user interaction is required.
What could an attacker achieve after exploitation?
An attacker could upload a web shell to the web server, which can lead to remote command execution. The reported impact includes high confidentiality, integrity, and availability impact.