Path Traversal Vulnerability in Tsinghua Unigroup Electronic Archives System
CVE-2026-3719
Key Information:
- Vendor
Tsinghua Unigroup
- Vendor
- CVE Published:
- 8 March 2026
Badges
What is CVE-2026-3719?
A path traversal vulnerability exists in Tsinghua Unigroup's Electronic Archives System version 3.2.210802(62532). This issue allows attackers to manipulate the argument path through the /System/Cms/downLoad file, potentially accessing unauthorized files on the server. The exploitation can be performed remotely, and publicly available exploits enhance the threat landscape. Despite early communication, the vendor has not addressed this vulnerability, raising concerns for users reliant on this product.
Affected Version(s)
Electronic Archives System 3.2.210802(62532)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
