Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-75327: DocSys Master 2.02.85 can let attackers upload any file

CVE-2026-75327 · published 8 days ago
Summary

The part of DocSys that lets users add pictures to markdown documents does not check what kind of file is being uploaded. This allows a malicious user to place a script or other dangerous file on the server, potentially leading to unauthorized access or data loss. Apply the vendor's latest update or temporarily disable the picture‑upload feature until it is corrected.

Original advisory text
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published26 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Sources
CVE-2026-75327 · MITRE
Monitor software like this
Free during beta