Junglewise Threat Intelligence

CVE-2026-86272: Beijing Meite Software U+Smart Enjoyment WebSite unrestricted file upload

CVE-2026-86272 · Severity: high · CVSS 7.3 · Published 2026-09-07

Executive brief

Beijing Meite Software's U+Smart Enjoyment WebSite contains a file upload vulnerability in its image upload handler (/Report/Upload/UploadFormImg.ashx). An attacker can exploit this to upload arbitrary files to the server over the network, potentially enabling remote code execution or website defacement. The vulnerability is remotely exploitable without authentication and has already been publicly disclosed.

Technical details

The vulnerability is an unrestricted file upload flaw in the UploadFormImg.ashx endpoint, which fails to properly validate the File parameter. An attacker can manipulate the File argument to bypass upload restrictions and upload malicious files to the web server. No authentication or special user interaction is required; the attack is directly accessible over the network. Successful exploitation allows an attacker to upload shell scripts or other executable content, leading to remote code execution or compromise of the web application. The vulnerability affects version 18.6001.1096.1000 and patches or mitigations are not yet confirmed.

Affected products

  • Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000

Timeline

  • 2026-09-07: disclosed

References