External risk intelligence

DocSys V2.02.85 Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75327

The vulnerability exists in an upload interface within a web application controller. Such endpoints are commonly exposed as part of internet-facing web applications or document management portals to allow user interactions, making public internet reachability a common deployment pattern for this type of functionality.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a document management system, specifically affecting an interface used for uploading images. This issue could allow unauthorized access and manipulation of files within the system, posing a risk to data integrity and confidentiality. The main concern at this time is to determine if our organization utilizes this specific technology and, if so, to what extent.

  • Arbitrary file uploads can compromise systems.
  • Critical vulnerability; confirm relevance and exposure.
  • Understand system exposure and potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to the `uploadMarkdownPic` interface. This interface, exposed through the web application's controller, allows users to upload images. If an attacker uploads a malicious file disguised as an image, the system may not properly validate it, potentially leading to the execution of arbitrary code or other severe consequences.

  • Requires network access.
  • Uploading a malicious file.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload arbitrary files through the `uploadMarkdownPic` interface. This may impact the integrity and availability of the affected system.

  • System files could be overwritten or replaced.
  • Arbitrary files may be uploaded remotely.
  • Service availability could be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the DocSys-master upload interface requires immediate attention from infrastructure and application owners. The first practical step is to determine the extent of its deployment, confirm its exposure and business criticality, and identify the accountable party for remediation planning.

  • Application owners should own this issue.
  • Verify external reachability and critical assets first.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DocSys-master?

DocSys-master is a document management software suite used for organizing and storing digital files. Specifically, version V2.02.85 includes a Java-based web controller component designed to handle user interactions, such as managing images within documentation. Because it functions as a centralized repository, it is often deployed to facilitate remote team collaboration and file sharing across an organization's network.

What does CWE-434 mean for CVE-2026-75327?

CWE-434 refers to Unrestricted Upload of File with Dangerous Type. In the context of this CVE, it means the DocSys-master software fails to adequately inspect or restrict files sent to the uploadMarkdownPic interface. Because the system does not verify that an uploaded file is truly an image, it may accept and save malicious code, allowing that file to be processed or executed by the server.

How is the uploadMarkdownPic interface triggered?

An attacker triggers this vulnerability by sending a specially crafted HTTP request directly to the uploadMarkdownPic interface. Successful exploitation requires the ability to reach this network endpoint and provide a file payload. The vulnerability is not triggered by simply browsing the application; it requires the active submission of a malicious file that the application incorrectly processes as a legitimate upload.

Is my instance of DocSys-master at risk?

Halo Surface Signal notes that since the flaw exists in a web-based upload controller, instances accessible from the public internet are at higher risk. If your DocSys-master installation is configured to allow remote user interactions via the web, it is considered internet-facing. Internal-only deployments that are strictly isolated from external network access have a lower likelihood of being reached by remote, unauthenticated attackers.

What should I do if I run DocSys-master?

First, verify your inventory to confirm if you are running version V2.02.85. If confirmed, identify the business owners for the system and check if the interface is reachable via the internet. Prioritize limiting access to the upload controller until you can coordinate with your technical team to assess the impact on your data integrity and determine the necessary steps for security remediation.

References