Unauthorized File Upload Vulnerability in U+Smart Enjoyment Website

Unauthorized File Upload Vulnerability in U+Smart Enjoyment Website

First seen 7 Sep 2026, 10:21 UTC Redpacketsecurityucn9h68n9289.feishu.cnvuldb.com 57.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2026-86272, has been identified in the U+Smart Enjoyment Website developed by Beijing Meite Software Technology. The vulnerability allows for unauthorized file uploads via the /Report/Upload/UploadFormImg.ashx interface, which lacks proper validation and filtering. Attackers can exploit this flaw to upload malicious files, potentially leading to remote code execution, server takeover, and data leakage. The vulnerability is particularly concerning for organizations using this platform on public-facing Windows web servers. Although the immediate impact is assessed as limited, the risk of exploitation is heightened due to public disclosure. No active exploitation has been reported yet, but the potential for opportunistic attacks exists. Organizations are advised to review their upload logs and apply mitigations as soon as possible.

Key Points: • CVE-2026-86272 allows unauthorized file uploads on U+Smart Enjoyment Website. • The vulnerability can lead to remote code execution and server takeover. • Organizations using the affected platform are urged to apply mitigations immediately.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-86272 published
A vulnerability in U+Smart Enjoyment Website allows unauthorized file uploads, posing significant risks.
Redpacketsecurity
2026-09-07
Public disclosure of vulnerability
The vulnerability was publicly disclosed, increasing the risk of opportunistic attacks.
ucn9h68n9289.feishu.cn