PT-2026-94034 · Bc Security+1 · Empire

·

CVE-2026-92748

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BC Security Empire versions prior to 6.7.1
Description Authenticated operators can write files to arbitrary paths on the C2 server because the software fails to validate the multipart filename parameter in upload endpoints. By using path traversal sequences—a technique used to access files and directories outside the intended folder—in the filename, attackers can bypass directory containment and write malicious files to sensitive locations to achieve code execution.
Recommendations Update BC Security Empire to version 6.7.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92748

Affected Products

Empire