Junglewise Threat Intelligence

CVE-2026-80235: Thinking Software Technology EFence arbitrary file upload

CVE-2026-80235 · Severity: critical · CVSS 9.8 · Published 2026-08-26

Technologies: Thinking Software Technology EFence. Vendors: Thinking Software Technology.

Executive brief

EFence is a web application security tool used to protect and monitor enterprise servers. An unauthenticated attacker can bypass security controls and upload malicious web shell files, leading to complete compromise of the server and arbitrary code execution. This allows attackers to take full control of the system, steal data, and establish persistent backdoor access without requiring any credentials.

Technical details

CVE-2026-80235 is an arbitrary file upload vulnerability in EFence version 1.2.66 and earlier that allows unauthenticated remote attackers to upload and execute web shell backdoors. The vulnerability exists due to insufficient validation of uploaded files and lacks proper authentication checks on the upload endpoint. Attack vector is network-based with no authentication required, no user interaction needed, and no complexity barriers (CVSS vector AV:N/AC:L/PR:N/UI:N). Successful exploitation results in arbitrary code execution on the server with full system compromise. A patch is available in version 1.2.67 DB Ver:57 and later.

Affected products

  • Thinking Software Technology EFence 1.2.66 DB Ver:56 and earlier

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Fix available in version 1.2.67 DB Ver:57 and later

References

Related threats