← Back to overview

EFence, a product developed by Thinking Software Technology, contains a critical Arbitrary File Upload vulnerability tracked as CVE-2026-80235. The vulnerability allows unauthenticated remote attackers to upload malicious files, specifically web shell backdoors, to the affected server. Once uploaded, these web shells can be executed, granting attackers the ability to run arbitrary code on the server. No authentication is required to exploit this vulnerability, significantly increasing its risk. The flaw poses a severe threat to organizations using EFence, as full server compromise is possible. Details have been published via Taiwan's TWCERT/CC advisory pages in both English and Traditional Chinese. The vulnerability is listed on the NVD (National Vulnerability Database) at NIST.

Affected products

  • EFence by Thinking Software Technology

Related CVE's

  • CVE-2026-80235

Categories

  • Enterprise Applications
  • Web Technologies
  • Zero-Day Vulnerabilities