← Vulnerability feed

Vulnerability record · CVE-2020-26806 · published 31 July 2021

CVE-2020-26806: Objectplanet opinio path traversal vulnerability

OObjectplanet · Opinio

admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.

8.8 CVSS 3.1 High EPSS 6.0% · top 7.0% CWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 6.5
6.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-26806 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-4472Objectplanet opinio vulnerabilityObjectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which c…EPSS 0.74%7.5CVE-2020-26565Objectplanet opinio expression language injection vulnerabilityObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve pos…EPSS 1.7%6.5CVE-2020-26564Objectplanet opinio xml external entity (xxe) vulnerabilityObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic sur…EPSS 1.1%6.1CVE-2020-26563Objectplanet opinio cross-site scripting vulnerabilityObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored X…EPSS 0.98%6.1CVE-2017-10798Objectplanet opinio cross-site scripting vulnerabilityIn ObjectPlanet Opinio before 7.6.4, there is XSS.EPSS 0.64%4.8CVE-2025-13873Objectplanet opinio cross-site scripting vulnerabilityStored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject a…EPSS 0.20%2.3CVE-2025-13871Objectplanet opinio cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the con…EPSS 0.18%2.1CVE-2025-13872Objectplanet opinio server-side request forgery (ssrf) vulnerabilityBlind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker …EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2020-26806), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.