{"id":"CVE-2026-92970","published":"2026-09-17T14:18:02.997","lastModified":"2026-09-22T20:53:07.383","description":"HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/hubzero/hubzero-cms","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/components/com_projects/api/controllers/filesv1_0.php#L809-L880","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/libraries/Hubzero/Filesystem/Entity.php#L53-L73","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/plugins/projects/files/connections.php#L812-L815","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/commit/4a58215463e5d42f8d03567358171383da939946","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/commit/5b4c4aefedf647390465cdfd0e7fa626c3e1cb39","tags":[]},{"url":"https://www.vulncheck.com/advisories/hubzero-cms-through-2.2.32-path-traversal-via-file-upload","tags":[]}],"exploitRefs":[{"url":"https://github.com/hubzero/hubzero-cms","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/components/com_projects/api/controllers/filesv1_0.php#L809-L880","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/libraries/Hubzero/Filesystem/Entity.php#L53-L73","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/plugins/projects/files/connections.php#L812-L815","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/commit/4a58215463e5d42f8d03567358171383da939946","tags":[]},{"url":"https://github.com/hubzero/hubzero-cms/commit/5b4c4aefedf647390465cdfd0e7fa626c3e1cb39","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows authenticated project members to write arbitrary files outside the project repository, potentially leading to code execution.","exploitability":"Exploitation requires authentication and knowledge of traversal sequences, making it moderately difficult.","blast_radius":"If exploited, attackers could gain code execution privileges, impacting the entire web server.","remediation":"Upgrade to HUBzero CMS 2.2.33 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","auth","upload"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:09:45.768Z"}}