🔐 CVE Alert

CVE-2026-92532

UNKNOWN 0.0

Unrestricted Upload of File with Dangerous Type in BugTracker.NET

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could upload a malicious ASPX file and subsequently execute it on the server. A successful exploit could allow arbitrary code execution with the privileges of the account used by the web service.

CWE CWE-434
Vendor bugtracker.net
Product bugtracker.net
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for bugtracker.net bugtracker.net

Be the first to know when new unknown vulnerabilities affecting bugtracker.net bugtracker.net are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

BugTracker.NET / BugTracker.NET
all versions

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bugtrackernet

Credits

Álvaro Monforte de la Huerga Juan Gabriel Ruiz Fernández