A critical unrestricted file upload vulnerability has been identified in Beijing Meite Software Technology's U+Smart Enjoyment WebSite version 18.6001.1096.1000. The vulnerability exists in the file /Report/Upload/UploadFormImg.ashx, where manipulation of the 'File' argument allows attackers to upload arbitrary files without restriction. The flaw can be exploited remotely, making it accessible to a wide range of threat actors. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been catalogued under CVE-2026-86272 and tracked in VulDB as entry 399431. No authentication bypass or additional prerequisites are detailed, suggesting the attack surface may be broad. Organizations using this software should apply patches or mitigations immediately. The unrestricted upload capability could allow attackers to upload malicious scripts or web shells, potentially leading to full system compromise.