CVE-2026-6835: Aenrich A+hcm
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
Affected products
- Aenrich A+hcm: up to and including 8.1
Published 2026-04-22. Last modified 2026-06-17.