PT-2026-99810 · Unknown · Eba Document/Workflow Management System

CVE-2026-85134

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eBA Plus Document and Workflow Management System versions 6.7.141 through 10.0.10
Description An unrestricted upload of files with dangerous types allows an attacker to upload a web shell to the web server, which can lead to remote command execution.
Recommendations Update eBA Plus Document and Workflow Management System to version 10.0.11 or later.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85134

Affected Products

Eba Document/Workflow Management System