CVE-2026-92970
8.8 HIGHpublic exploit availablePublished 2026-09-17 · Updated 2026-09-22
AI risk analysis
- Summary
- This vulnerability allows authenticated project members to write arbitrary files outside the project repository, potentially leading to code execution.
- Exploitability
- Exploitation requires authentication and knowledge of traversal sequences, making it moderately difficult.
- Blast radius
- If exploited, attackers could gain code execution privileges, impacting the entire web server.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to HUBzero CMS 2.2.33 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Public exploit & PoC references
- https://github.com/hubzero/hubzero-cms
- https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/components/com_projects/api/controllers/filesv1_0.php#L809-L880
- https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/libraries/Hubzero/Filesystem/Entity.php#L53-L73
- https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/plugins/projects/files/connections.php#L812-L815
- https://github.com/hubzero/hubzero-cms/commit/4a58215463e5d42f8d03567358171383da939946
- https://github.com/hubzero/hubzero-cms/commit/5b4c4aefedf647390465cdfd0e7fa626c3e1cb39
All references
- https://github.com/hubzero/hubzero-cms
- https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/components/com_projects/api/controllers/filesv1_0.php#L809-L880
- https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/libraries/Hubzero/Filesystem/Entity.php#L53-L73
- https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/plugins/projects/files/connections.php#L812-L815
- https://github.com/hubzero/hubzero-cms/commit/4a58215463e5d42f8d03567358171383da939946
- https://github.com/hubzero/hubzero-cms/commit/5b4c4aefedf647390465cdfd0e7fa626c3e1cb39
- https://www.vulncheck.com/advisories/hubzero-cms-through-2.2.32-path-traversal-via-file-upload
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-12264
- CRITICALCVE-2026-14175
- CRITICALCVE-2026-18143
- CRITICALCVE-2026-20305
- HIGHCVE-2026-54416PoC
- HIGHCVE-2026-6147
- CRITICALCVE-2026-70356PoC
- CRITICALCVE-2026-82187
Related by shared AI tags and CWE weakness class. Browse the full archive.