File Download Vulnerability in OPEXUS eComplaint by OPEXUS
CVE-2026-22235
8.7HIGH
What is CVE-2026-22235?
The OPEXUS eComplaint software prior to version 9.0.45.0 is susceptible to an improper access control vulnerability. This flaw allows attackers to exploit the 'DocumentOpen.aspx' endpoint by guessing predictable values for 'chargeNumber'. As a result, unauthorized users can access and download arbitrary uploaded files, potentially exposing sensitive information. Organizations using vulnerable versions are advised to upgrade to mitigate the risk.
Affected Version(s)
eComplaint 0 < 9.0.45.0
eComplaint 9.0.45.0
