Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Tsinghua Unigroup Archives System Allows Remote File Access

CVE-2026-2672
Summary

A security flaw in the Tsinghua Unigroup Archives System lets hackers access and download sensitive files on your system from anywhere. This is a serious issue because it allows attackers to access and potentially steal confidential data. We recommend that you update your system to the latest version as soon as possible to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
unigroup electronic_archives_system <= 3.2.210802\(62532\) –
Original title
A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/Subject/downLoad. ...
Original description
A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/Subject/downLoad. Performing a manipulation of the argument path results in path traversal. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 4.0
nvd CVSS3.1 5.3
nvd CVSS4.0 5.3
Vulnerability type
CWE-22 Path Traversal
Published: 18 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026