CVE-2026-101071
Deferred Deferred - Pending Action

Unrestricted File Upload in Acrel Electric Unet Web Service

Vulnerability report for CVE-2026-101071, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
acrel unet_web_service to 20260814 (inc)
acrel electric_unet_web_service to 20260814 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated file upload flaw in Acrel Electric Unet Web Service up to version 20260814. The /exchange/attachment/upload endpoint allows attackers to upload arbitrary files, including malicious JSP files, without authentication or file type validation. The server accepts and stores these files without restrictions, enabling potential remote code execution if the uploaded file is accessed.

Detection Guidance

Check for unauthorized file uploads to the /exchange/attachment/upload endpoint. Monitor network traffic for POST requests to this path with file attachments. Inspect server directories for unexpected JSP or executable files in web-accessible locations.

Impact Analysis

An attacker could exploit this to upload malicious files to your server, leading to remote code execution. This could allow unauthorized access to your system, data theft, or further compromise of your network. The lack of authentication requirements means anyone on the internet could attempt this attack.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Non-compliance with these regulations can result in significant fines and legal consequences.

Mitigation Strategies

Disable or restrict access to the /exchange/attachment/upload endpoint. Implement strict file type validation to block executable files like JSP. Require authentication for file uploads and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart