CVE-2026-6835: Aenrich A+hcm

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.

Affected products

  • Aenrich A+hcm: up to and including 8.1

Published 2026-04-22. Last modified 2026-06-17.