CVE-2026-75413
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
Published 2026-08-26. Last modified 2026-09-09.