Description
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server.

This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Published: 2026-09-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to upload a file of a dangerous type, such as a web shell, to the server. Once uploaded, the shell can be executed, giving the attacker the ability to run arbitrary commands on the host. This flaw represents an unauthorized code execution scenario and is classified as CWE-434.

Affected Systems

The issue affects the Bimser Solution Software Trade Inc. eBA Plus Document and Workflow Management System. Vulnerable implementations are present in releases from version 6.7.141 up to and including 10.0.10. Versions 10.0.11 and later are not affected.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed exploitation reports yet. The attack vector is inferred to be via the web upload interface, requiring access to the upload functionality; after upload, execution is possible if the web server interprets the file as executable.

Generated by OpenCVE AI on September 28, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade eBA Plus to version 10.0.11 or later, which removes the upload flaw.
  • Configure the web server to prevent execution of files in the upload directory, for example by disabling script execution or setting the directory to serve only static content.
  • Implement server‑side validation of MIME types and reject any file types that are not explicitly allowed.
  • Regularly audit the upload directory for unexpected executables or scripts and block them if found.

Generated by OpenCVE AI on September 28, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Title Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-28T13:31:29.808Z

Reserved: 2026-09-03T08:44:26.197Z

Link: CVE-2026-85134

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:25.455Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T09:17:07.380

Modified: 2026-09-28T14:31:05.267

Link: CVE-2026-85134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T09:30:14Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type