DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
History

Wed, 02 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated File Download via DownloadDocEx in DocSys 2.02.80
Weaknesses CWE-200
CWE-284

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-552
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated File Download via DownloadDocEx in DocSys 2.02.80
Weaknesses CWE-200
CWE-284

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-08-26T00:00:00.000Z

Updated: 2026-09-01T18:53:04.137Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75413

cve-icon Vulnrichment

Updated: 2026-09-01T18:52:27.889Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T21:16:41.217

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-75413

cve-icon Redhat

No data.