CVE-2026-32867

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. Uploading a large number of files could consume storage.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opexustech:ecase_ecomplaint:*:*:*:*:*:*:*:*

History

30 Mar 2026, 13:10

Type Values Removed Values Added
First Time Opexustech ecase Ecomplaint
Opexustech
CPE cpe:2.3:a:opexustech:ecase_ecomplaint:*:*:*:*:*:*:*:*
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-077-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-077-01.json - Broken Link
References () https://www.cve.org/CVERecord?id=CVE-2026-32867 - () https://www.cve.org/CVERecord?id=CVE-2026-32867 - Third Party Advisory

Information

Published : 2026-03-19 16:16

Updated : 2026-03-30 13:10


NVD link : CVE-2026-32867

Mitre link : CVE-2026-32867

CVE.ORG link : CVE-2026-32867


JSON object : View

Products Affected

opexustech

  • ecase_ecomplaint
CWE
CWE-425

Direct Request ('Forced Browsing')

CWE-639

Authorization Bypass Through User-Controlled Key