Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-92980: HortusFox-Web allows admins to run any command

CVE-2026-92980 · published 11 days ago
Summary

In versions before 6.1, an admin who uses the Import/Export feature can cause the web server to execute any operating‑system command. This could let an attacker place and run malicious code on the server hosting the application. Upgrade to version 6.1 or later, or restrict admin access to the import/export function, to eliminate the risk.

What to do
  • Update danielbrendel hortusfox-web to version 6.1 or later.
Affected software
VendorProductAffected versions
danielbrendel hortusfox-web < 6.1
Original advisory text
HortusFox-Web < 6.1 Remote Code Execution via Import/Export
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.
Severity
8.6 High
CVSS 3.1: 7.2 (NVD)
CVSS 4.0: 8.6 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published17 Sep 2026
Updated29 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-92980 · MITRE
Track software like this
Free during beta