Description
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 9.0.45.0
9.0.45.0
Credits
Zach Crosman, CISA
References
www.cve.org/CVERecord?id=CVE-2026-22234 (url)
raw.githubusercontent.com/...IT/white/2025/va-26-008-02.json (url)