CVE-2026-32867
Severity CVSS v4.0:
MEDIUM
Type:
CWE-425
Direct Request ('Forced Browsing')
Publication date:
19/03/2026
Last modified:
20/03/2026
Description
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. Uploading a large number of files could consume storage.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
5.40
Severity 3.x
MEDIUM



