Unrestricted File Upload in Acrel Electric Unet Web Service
CVE-2026-101071
Key Information:
- Vendor
Acrel Electric
- Status
- Vendor
- CVE Published:
- 28 September 2026
Badges
What is CVE-2026-101071?
Acrel Electric Unet Web Service up to version 20260814 contains a vulnerability in the Upload Endpoint that allows for unrestricted file uploads through the manipulation of file arguments in the /exchange/attachment/upload path. This security flaw can be exploited by remote attackers, exposing the system to rigorous security threats such as unauthorized access and malicious code execution. The exploit has been publicly disclosed, raising significant concerns for users and administrators of the affected service. Despite early notification to the vendor, there has been no response to mitigate this vulnerability.
Affected Version(s)
Unet Web Service 20260814
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
