Sceawere

Vulnerability Detail

CVE-2026-85134UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

eBA Plus Unrestricted File Upload

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Bimser Solution Software Trade Inc.
Product
eBA Plus Document and Workflow Management System
Attack Type
CWE-434 Unrestricted upload of file with dangerous type
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-28T09:17:07.380Z",
  "pubdate": "2026-09-28T09:17:07.380Z",
  "executiveSummary": "The eBA Plus Document and Workflow Management System is susceptible to an unrestricted file upload vulnerability, allowing unauthorized actors to upload dangerous file types to the web server.\nThis vulnerability stems from insufficient validation of user-supplied files, potentially enabling remote code execution (RCE) through the deployment of web shells.\nThe flaw affects versions of eBA Plus Document and Workflow Management System from 6.7.141 prior to 10.0.11.\nSuccessful exploitation permits an attacker to execute arbitrary code within the context of the web server process, leading to full system compromise, data exfiltration, or unauthorized workflow manipulation.\nThis represents a high-severity security risk as it facilitates persistent access and lateral movement within the enterprise environment.\nThe vulnerability requires interaction with the system's file upload interface, though exploitation may be achieved without advanced credentials depending on the specific configuration of the upload endpoint.",
  "technicalDetails": "The vulnerability resides in the file handling mechanism of the eBA Plus Document and Workflow Management System. The application fails to perform rigorous server-side validation on the MIME type, file extension, or content of uploaded files, allowing an attacker to bypass intended security controls.\nThe root cause is an inadequate implementation of allow-listing for file extensions and content-type verification. By manipulating the upload request, an attacker can bypass front-end or client-side checks to place executable scripts—such as .aspx, .ashx, or other server-side scripting files—directly into the web root or a directory accessible by the web server process.\nThe attack flow initiates when an authenticated or unauthenticated attacker targets an exposed file upload endpoint within the eBA application. The attacker submits a crafted HTTP POST request containing a malicious payload disguised as a legitimate file. Once the server saves the file to the disk, the attacker executes the payload by requesting the specific file path via a standard web browser or automated tool.\nUpon successful execution, the web shell grants the attacker an interactive command-line interface to the underlying operating system. This allows for the execution of arbitrary system commands, traversal of the filesystem, modification of application databases, and credential harvesting from system memory.\nAffected versions include eBA Plus Document and Workflow Management System from 6.7.141 before 10.0.11. The scope of impact is limited to environments where the web server configuration allows the execution of user-supplied scripts in the designated upload directories.\nPost-exploitation impact includes persistent backdooring of the server, potential escalation of privileges if the web server process is running with excessive permissions, and the compromise of sensitive documents and workflows managed by the eBA system."
}
CVE-2026-85134: eBA Plus Unrestricted File Upload (HIGH Severity, CVSS: 8.8) | Sceawere