PT-2026-94335 · Unknown · Hubzero-Cms

·

CVE-2026-92970

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HUBzero CMS versions prior to 2.2.33
Description A path traversal issue exists in project file upload handlers. This allows authenticated project members to write arbitrary files outside the project repository by supplying traversal sequences in upload parameters. This action is performed with web server privileges and could potentially lead to code execution.
Recommendations Update HUBzero CMS to version 2.2.33 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92970

Affected Products

Hubzero-Cms