CVE-2025-6076: Partner Software Partner Web

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a malicious file and compromise the device. By default, the software runs as SYSTEM, heightening the severity of the vulnerability.

Affected products

Published 2025-08-02. Last modified 2026-06-17.