← Terug naar overzicht

A critical unrestricted file upload vulnerability has been identified in Beijing Meite Software Technology's U+Smart Enjoyment WebSite version 18.6001.1096.1000. The vulnerability exists in the file /Report/Upload/UploadFormImg.ashx, where manipulation of the 'File' argument allows attackers to upload arbitrary files without restriction. The flaw can be exploited remotely, making it accessible to a wide range of threat actors. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been catalogued under CVE-2026-86272 and tracked in VulDB as entry 399431. No authentication bypass or additional prerequisites are detailed, suggesting the attack surface may be broad. Organizations using this software should apply patches or mitigations immediately. The unrestricted upload capability could allow attackers to upload malicious scripts or web shells, potentially leading to full system compromise.

Affected products

  • Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000

Related CVE's

  • CVE-2026-86272

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities