CVE-2026-22234

CRITICAL

OPEXUS eCasePortal <9.0.45.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
opexustech/ecase_portal < 9.0.45.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026