CVE-2026-4201
glowxq glowxq-oj SysFileController.java upload unrestricted upload
Description
A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFileController.java. Executing a manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsen·The Hacker News·
- Three JFrog Artifactory Flaws Exploited for Backdoor Deploymenten-us·SecurityWeek· Exploited JFrog Artifactory auth-bypass
- Artifactory flaws chained in attacks deploying backdoor malwareen-us·BleepingComputer· Exploited JFrog Artifactory auth-bypass
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoorsen·The Hacker News· Exploited JFrog Artifactory rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-4201 and every CVE in our database. Create a free account — no credit card required.
Create Free Account