๐Ÿ” CVE Alert

CVE-2026-2731

UNKNOWN 0.0

Unauthenticated RCE in Dynamicweb 9 and Dynamicweb 8

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests

CWE CWE-22
Vendor dynamicweb
Product dynamicweb 9
Published Feb 19, 2026
Last Updated Feb 19, 2026
Stay Ahead of the Next One

Get instant alerts for dynamicweb dynamicweb 9

Be the first to know when new unknown vulnerabilities affecting dynamicweb dynamicweb 9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

DynamicWeb / DynamicWeb 9
8 9 < 9.19.7 9.20.0 < 9.20.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
doc.dynamicweb.dev: https://doc.dynamicweb.dev/documentation/fundamentals/dw10release/security-reports.html#january-19th-2026---unauthenticated-rce-dynamicweb-9-and-dynamicweb-8

Credits

Jonas Vestberg, Reversec Sweden AB