CVE-2026-22234

CRITICAL

OPEXUS eCasePortal <9.0.45.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

References (2)

Core 2
Core References

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
opexustech/ecase_portal < 9.0.45.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026