CVE-2026-74845
8.82100 Technology · Official Document Management System
2100 Technology Official Document Management System contains an arbitrary file upload vulnerability allowing authenticated remote attackers to execute arbitrary code via web shell backdoors.
Executive summary
An arbitrary file upload vulnerability in the 2100 Technology Official Document Management System allows authenticated attackers to achieve remote code execution on the host server.
Vulnerability
The application fails to properly validate file types during upload, allowing an authenticated attacker with low privileges to upload malicious scripts. These scripts can be executed to gain persistent control over the server environment.
Business impact
The vulnerability poses a severe risk to organizational infrastructure, as successful exploitation results in total system compromise. With a CVSS score of 8.8, this flaw enables attackers to bypass security controls, steal sensitive documents, or pivot into the internal network, leading to significant reputational and operational damage.
Remediation
Immediate Action: Update the Official Document Management System to version 5.0.105 or later immediately.
Proactive Monitoring: Inspect web server logs for suspicious file upload requests or unexpected execution patterns in upload directories.
Compensating Controls: Implement strict file type validation and execution restrictions on web directories via a Web Application Firewall or server configuration to prevent the execution of unauthorized scripts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for full server takeover, organizations must prioritize upgrading to version 5.0.105. Failure to patch this vulnerability leaves the environment exposed to unauthorized command execution by any actor possessing valid application credentials.