{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/eba-plus-document-and-workflow-management-system-6.7.141---10.0.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bimser_solution_software_trade:eba_plus_document_and_workflow_management_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-85134"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["eBA Plus Document and Workflow Management System (6.7.141 - 10.0.10)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","web-application"],"_cs_type":"advisory","_cs_vendors":["Bimser Solution Software Trade Inc."],"content_html":"\u003cp\u003eCVE-2026-85134 identifies a critical security flaw in Bimser Solution Software Trade Inc. eBA Plus Document and Workflow Management System, specifically affecting versions 6.7.141 through 10.0.10. The vulnerability stems from improper validation of user-supplied files during the upload process. An unauthenticated attacker can exploit this weakness to upload executable scripts, such as web shells, directly to the web server's directory. Once the malicious file is uploaded, the attacker can trigger its execution by requesting the file path via the web server. Successful exploitation results in remote code execution (RCE) with the privileges of the web application service account. This allows for total system compromise, data exfiltration, or the establishment of persistent backdoors within the organization's environment. Defenders should prioritize patching affected instances to version 10.0.11 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to organizations utilizing eBA Plus for document and workflow management. Exploitation allows unauthenticated attackers to gain remote code execution, leading to potential unauthorized access to sensitive documents, workflow metadata, and underlying server infrastructure. If exploited, an attacker could maintain persistent access to the system, modify corporate workflows, or exfiltrate intellectual property. No specific victim count is documented, but the nature of the software makes it a target for attackers seeking access to sensitive enterprise data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch eBA Plus Document and Workflow Management System to version 10.0.11 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit web server upload directories for unauthorized script files (e.g., .aspx, .php, .jsp) created by the web application service account.\u003c/li\u003e\n\u003cli\u003eRestrict write permissions on the web server directory to prevent the execution of files uploaded to temporary or user-accessible paths.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to document upload endpoints that result in 200 OK statuses or contain unexpected file extensions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T10:15:49Z","date_published":"2026-09-28T10:15:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85134/","summary":"An unrestricted file upload vulnerability in Bimser Solution Software Trade Inc. eBA Plus Document and Workflow Management System allows unauthenticated attackers to execute arbitrary code via web shell deployment.","title":"Unrestricted File Upload Vulnerability in eBA Plus","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85134/"}],"language":"en","title":"CraftedSignal Threat Feed - EBA Plus Document and Workflow Management System (6.7.141 - 10.0.10)","version":"https://jsonfeed.org/version/1.1"}