---
id: CVE-2026-8233
title: A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4
summary: >-
  A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4.
  Affected is an unknown function of the component UPF. This manipulation causes
  improper access controls. A high degree of complexity is needed for the
  attack. The …
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-284
published: '2026-05-10'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8233'
references:
  - url: 'https://vuldb.com/submit/808799'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362450'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362450/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/808799'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0019
epssPercentile: 0.08929
ingestedAt: '2026-07-24T07:21:21.372Z'
---

## Overview

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacted early about this disclosure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
