CVE-2026-92532
Received Received - Intake

Unrestricted File Upload in BugTracker.NET Leading to RCE

Vulnerability report for CVE-2026-92532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could upload a malicious ASPX file and subsequently execute it on the server. A successful exploit could allow arbitrary code execution with the privileges of the account used by the web service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
BugTracker.NET BugTracker.NET all versions

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unrestricted file upload vulnerability in BugTracker.NET's attachment feature. An authenticated admin can modify settings to store files in a web-accessible directory. Without proper file extension checks, an attacker could upload a malicious ASPX file and execute it on the server, leading to arbitrary code execution with the web service's privileges.

Detection Guidance

Check for unexpected ASPX files in web-accessible directories, especially in BugTracker.NET attachment folders. Review server logs for unusual file uploads or modifications to application configuration files.

Impact Analysis

If exploited, this vulnerability allows attackers to run arbitrary code on the server with the privileges of the web service account. This could lead to full system compromise, data theft, or further network infiltration. The impact depends on the server's configuration and the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face legal penalties, reputational damage, and loss of compliance certifications if exploited.

Mitigation Strategies

Disable file upload functionality for non-administrative users. Implement strict file extension validation to block ASPX and other executable file types. Restrict web directory permissions to prevent execution of uploaded files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart