CVE-2026-90500: Unrestricted Upload in lenve vhr
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability in lenve vhr 1.0-SNAPSHOT involves the FastDFSUtils.upload function within the Avatar Upload component, specifically in the /hr/userface file. An attacker can remotely manipulate the File argument to upload files without restriction, potentially leading to unauthorized file uploads. The vulnerability has been publicly disclosed with an available exploit. The vendor was contacted but did not provide any response or patch information.
Potential Impact
The vulnerability allows remote attackers to upload files without restriction, which could lead to unauthorized file storage on the server. This may facilitate further attacks such as code execution or data compromise depending on the server configuration and file handling. However, no confirmed in-the-wild exploitation has been reported.
Mitigation Recommendations
No official patch or remediation is currently available as the vendor has not responded to disclosure. Users should consider restricting access to the affected upload functionality, implementing additional validation or filtering on uploaded files, or disabling the Avatar Upload feature until a fix is provided. Monitor vendor channels for updates.
CVE-2026-90500: Unrestricted Upload in lenve vhr
Description
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 5.3medium
Affected software
lenve
vhr
cpe:2.3:a:lenve:vhr:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in lenve vhr 1.0-SNAPSHOT involves the FastDFSUtils.upload function within the Avatar Upload component, specifically in the /hr/userface file. An attacker can remotely manipulate the File argument to upload files without restriction, potentially leading to unauthorized file uploads. The vulnerability has been publicly disclosed with an available exploit. The vendor was contacted but did not provide any response or patch information.
Potential Impact
The vulnerability allows remote attackers to upload files without restriction, which could lead to unauthorized file storage on the server. This may facilitate further attacks such as code execution or data compromise depending on the server configuration and file handling. However, no confirmed in-the-wild exploitation has been reported.
Mitigation Recommendations
No official patch or remediation is currently available as the vendor has not responded to disclosure. Users should consider restricting access to the affected upload functionality, implementing additional validation or filtering on uploaded files, or disabling the Avatar Upload feature until a fix is provided. Monitor vendor channels for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-12T08:24:09.879Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa654f755bf5e2cf555f974
Added to database: 09/13/2026, 07:47:03 UTC
Last enriched: 09/13/2026, 08:01:26 UTC
Last updated: 09/14/2026, 03:06:17 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.