CVE-2026-22235

HIGH

OPEXUS eComplaint <9.0.45.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
opexustech/ecase_ecomplaint < 9.0.45.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026