{"id":"CVE-2026-86272","title":"A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000","summary":"A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument Fil…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-284","CWE-434"],"vendor":"Beijing Meite Software Technology","product":"U+Smart Enjoyment WebSite","affected":["u+smart_enjoyment_website 18.6001.1096.1000"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T14:17:33.600","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86272","references":[{"url":"https://ucn9h68n9289.feishu.cn/wiki/IYaowPR6licbC3kdw3xcJpQ7n6b?from=from_copylink","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-86272","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/904145","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399431","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399431/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T13:42:52.678055Z"},"epss":0.00383,"epssPercentile":0.32183,"ingestedAt":"2026-09-08T15:33:26.975Z","slug":"CVE-2026-86272","body":"## Overview\n\nA vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}