Junglewise Threat Intelligence

CVE-2026-80237: Thinking Software Technology EFence arbitrary file upload

CVE-2026-80237 · Severity: high · CVSS 8.8 · Published 2026-08-26

Technologies: Thinking Software Technology EFence. Vendors: Thinking Software Technology.

Executive brief

EFence is a web-based security application developed by Thinking Software Technology. An authenticated attacker can upload and execute malicious web shell files on the server, enabling arbitrary code execution. This allows an attacker with valid credentials to completely compromise the server and potentially access sensitive data or disrupt operations.

Technical details

CVE-2026-80237 is an arbitrary file upload vulnerability in EFence affecting versions 1.2.66 DB Ver:56 and earlier. The vulnerability allows authenticated remote attackers to upload and execute web shell backdoors on the server without restriction, leading to remote code execution. The attack requires valid user authentication (PR:L in CVSS vector) but no user interaction. The vulnerability can be exploited over the network to gain full control of the affected server. A patch is available in version 1.2.67 DB Ver:57 and later.

Affected products

  • Thinking Software Technology EFence 1.2.66 DB Ver:56 and earlier

Timeline

  • 2026-08-26: disclosed: Published by TWCERT/CC

References

Related threats