CVE-2026-22235: Opexustech Ecase Ecomplaint

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

Affected products

  • Opexustech Ecase Ecomplaint: before 9.0.45.0 (fixed in 9.0.45.0)

Published 2026-01-08. Last modified 2026-06-17.