PT-2026-93877 · Stamusnetworks · Scirius

·

CVE-2026-92604

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path traversal sequences in the uploaded document's id field to escape the intended directory and write files with .json extension to arbitrary locations as root.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92604

Affected Products

Scirius