Executive brief
EFence is a web-based security application developed by Thinking Software Technology. An authenticated attacker can upload and execute malicious web shell files on the server, enabling arbitrary code execution. This allows an attacker with valid credentials to completely compromise the server and potentially access sensitive data or disrupt operations.
Technical details
CVE-2026-80237 is an arbitrary file upload vulnerability in EFence affecting versions 1.2.66 DB Ver:56 and earlier. The vulnerability allows authenticated remote attackers to upload and execute web shell backdoors on the server without restriction, leading to remote code execution. The attack requires valid user authentication (PR:L in CVSS vector) but no user interaction. The vulnerability can be exploited over the network to gain full control of the affected server. A patch is available in version 1.2.67 DB Ver:57 and later.
Affected products
- Thinking Software Technology EFence 1.2.66 DB Ver:56 and earlier
Timeline
- 2026-08-26: disclosed: Published by TWCERT/CC