CVE-2026-92970

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution.
Configurations

No configuration.

History

17 Sep 2026, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-17 14:18

Updated : 2026-09-17 14:18


NVD link : CVE-2026-92970

Mitre link : CVE-2026-92970

CVE.ORG link : CVE-2026-92970


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')