CVE-2026-85134
Received
Received - Intake
Unrestricted File Upload in Bimser eBA Plus
Vulnerability report for CVE-2026-85134, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-28
Last updated on: 2026-09-28
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server.
This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bimser_solution_software_trade_inc | eba_plus_document_and_workflow_management_system | From 6.7.141 (inc) to 10.0.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |