Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-92748: BC Security Empire 6.7.1 allows arbitrary file placement

CVE-2026-92748 · published 12 days ago
Summary

BC Security Empire versions before 6.7.1 let a signed-in user upload a file and choose any location on the server by putting ".." in the file name. This can let an attacker drop malicious files where they can be run, potentially taking control of the server. Upgrade to the latest version or apply the vendor’s patch and limit file‑upload permissions.

What to do
  • Update bc-security empire to version 6.7.1 or later.
Affected software
VendorProductAffected versions
bc-security empire < 6.7.1
Original advisory text
BC Security Empire before 6.7.1 Path Traversal File Upload RCE
BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive locations for code execution.
Severity
8.7 High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published16 Sep 2026
Updated27 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-92748 · MITRE
Track software like this
Free during beta