CVE-2026-6211

HIGH

Arbitrary File Upload in Global IT's WEOLL

Title source: cna
STIX 2.1

Description

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

References (1)

Core 1
Core References

Scores

CVSS v3 8.7
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Global IT Informatics Services Inc./WEOLL 2.0.9 - 3.2.45.33
Published Jun 12, 2026
Tracked Since Jun 12, 2026