CVE-2026-90500: lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the remote exploitation risk by restricting network access to the lenve vhr Avatar Upload userface endpoint (/hr/userface) that invokes FastDFSUtils.upload (e.g., allow only trusted IPs via firewall/ACL/reverse proxy), since the vulnerability enables unrestricted upload when accessed remotely.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely over the network and requires low-level privileges. No user interaction is required.
Is exploit code available?
Yes. A public exploit has been made available and could be used in attacks.
Is a vendor fix or response available?
No vendor response is reported. The vendor was contacted early in the disclosure process but did not respond.