THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-92970 (HIGH 8.8) — HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to at

[NVD] CVE-2026-92970 (HIGH 8.8) — HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to at

mednvdPublished 2026-09-17

CVE-2026-92970 CVSS: 8.8 HIGH Published: 2026-09-17T14:18:02.997

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potent

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92970