CVE-2026-92533
Received Received - Intake

Path Traversal in BugTracker.NET File Download

Vulnerability report for CVE-2026-92533, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to access files located outside the intended directory. Successful exploitation could allow the attacker to read system files accessible to the account used by the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
BugTracker.NET BugTracker.NET all versions

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-24 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in BugTracker.NET's file download component. The issue occurs because the application does not properly validate user-supplied file paths. An authenticated remote attacker can manipulate the path parameter to access files outside the intended directory. This could allow reading sensitive system files accessible to the application's account.

Detection Guidance

Check web server logs for unusual file access patterns or requests containing path traversal sequences like '../' or '..\'. Test the application by attempting to download files outside the intended directory using manipulated paths.

Impact Analysis

An attacker could exploit this to read sensitive files on the server, such as configuration files, logs, or other restricted data. This may lead to information disclosure, privilege escalation, or further attacks if credentials or keys are exposed. The impact depends on the permissions of the application's account.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data. GDPR may require breach notification if personal data is accessed. HIPAA could be violated if protected health information is exposed. Organizations must assess potential data exposure and implement mitigations to maintain compliance.

Mitigation Strategies

Apply input validation to the file download parameter to ensure only allowed paths are accessed. Restrict file system permissions for the application account to limit access to sensitive files. Update BugTracker.NET to the latest version if a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92533. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart