OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-85134

HIGH · CVSS 8.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The eBA Plus Document and Workflow Management System is vulnerable to an unrestricted file upload flaw, enabling attackers to upload a web shell to the web server. This could lead to remote code execution, potentially compromising the server and its data. Organizations using versions 6.7.141 through 10.0.11 should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-85134
Severity
HIGH
CVSS
8.8
EPSS
0.27%

Original NVD Description

Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.