Impact
The vulnerability is an arbitrary file upload flaw that allows privileged remote attackers to place and run web shell backdoors on the server, providing them with the ability to execute arbitrary code.
Affected Systems
The software affected is DigiWin’s EasyFlow .NET. The CVE does not list specific release numbers, but a patch was issued after April 16 2026. Users should verify they are running a version older than the patched release.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the lack of an EPSS score means the exact exploitation probability is unclear. The vulnerability is not yet in the CISA KEV catalog. Attackers would need remote access to upload files, implying that an exposed web application that allows file uploads could be leveraged. Since the flaw permits execution of arbitrary code, the impact is considerable if exploited.
OpenCVE Enrichment