Description
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unrestricted File Upload
Action: Patch
AI Analysis

Impact

The Unet Web Service processes file uploads from the /exchange/attachment/upload endpoint without validating the file type. This lack of validation allows an attacker to upload arbitrary files, which could be used to compromise confidentiality, integrity, and availability of the service. The weakness is identified by the Common Weakness Enumeration identifiers for Improper Access Control (CWE-284) and Untrusted File Upload (CWE-434).

Affected Systems

Acrel Electric Unet Web Service, versions up to 2026-08-14, are affected. The vulnerability exists in the Upload Endpoint for the /exchange/attachment/upload route, and the affected code is unknown beyond that component.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can be carried out remotely and is publicly disclosed, meaning attackers can readily target any exposed instance of the service. The lack of immediate vendor response further increases the window of exposure, making timely remediation critical.

Generated by OpenCVE AI on September 28, 2026 at 15:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Unet Web Service to a version newer than 2026-08-14 or apply the vendor-provided patch once it is released.
  • Implement file type whitelisting on the /exchange/attachment/upload endpoint to allow only trusted extensions as a direct mitigation of the untrusted file upload weakness.
  • Restrict network access to the web service by firewall rules or network segmentation so that only trusted hosts or networks can initiate uploads; consider disabling the upload endpoint entirely if unused.

Generated by OpenCVE AI on September 28, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Acrel Electric Unet Web Service Upload Endpoint upload unrestricted upload
First Time appeared Acrel Electric
Acrel Electric unet Web Service
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:acrel_electric:unet_web_service:*:*:*:*:*:*:*:*
Vendors & Products Acrel Electric
Acrel Electric unet Web Service
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Acrel Electric Unet Web Service
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T15:35:09.218Z

Reserved: 2026-09-27T17:41:33.466Z

Link: CVE-2026-101071

cve-icon Vulnrichment

Updated: 2026-09-28T15:34:59.482Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:13.770

Modified: 2026-09-28T16:17:11.633

Link: CVE-2026-101071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:12Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type