← Vulnerability feed

Vulnerability record · CVE-2022-36537 · published 26 August 2022

CVE-2022-36537: ZK Framework AuUploader information disclosure flaw

Zkoss · Zk Framework

ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allow attackers to access sensitive information through a crafted POST request to the AuUploader component. The record does not describe the underlying weakness beyond a generic CWE-Other label, but the flaw is remotely reachable without authentication and has been exploited in the wild.

7.5 CVSS 3.1 High CISA KEV since 27 Feb 2023 Known ransomware use EPSS 95% · top 0.1%
7.5CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityThe flaw is unauthenticated, remotely reachable, listed in CISA KEV with ransomware use, and has an EPSS probability above 0.95.

What it is

ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allow attackers to access sensitive information through a crafted POST request to the AuUploader component. The record does not describe the underlying weakness beyond a generic CWE-Other label, but the flaw is remotely reachable without authentication and has been exploited in the wild.

Impact

An unauthenticated attacker can read sensitive information exposed through the AuUploader endpoint. CISA's KEV entry and third-party reporting tie the flaw to remote code execution in real attacks, so the practical impact can extend beyond data exposure.

Attack surface

The flaw is reached over the network via a crafted POST request to the AuUploader component. The CVSS vector shows no privileges or user interaction required, so any reachable ZK Framework instance is exposed.

Exploitation

CVE-2022-36537 is listed in CISA KEV with a due date of 2023-03-20 and known ransomware campaign use, and EPSS gives it a 30-day probability of 0.954. References include a vendor patch and reporting on active exploitation of an RCE flaw in the same framework.

What to do

  • Apply the vendor patch referenced in ZK-5150 for the affected ZK Framework versions.
  • If patching is not immediately possible, restrict network access to AuUploader endpoints and block untrusted POST requests at the perimeter.
  • Upgrade to a supported ZK Framework release and verify the AuUploader component is not exposed unnecessarily.
  • Monitor for and isolate any host showing signs of post-exploitation activity given the KEV ransomware association.

Detection

  • Inspect web logs for POST requests to AuUploader paths from unexpected sources or with anomalous payloads.
  • Alert on outbound connections or process creation following AuUploader requests on ZK Framework hosts.
  • Hunt for known exploitation indicators against the ZK-5150 advisory and CISA KEV guidance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-36537 to the Known Exploited Vulnerabilities catalog on 27 February 2023 as "ZK Framework AuUploader Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 20 March 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36537 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-36537), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.