Operating System Command Injection Vulnerability in BugTracker.NET by Rojek
CVE-2026-92531

7.5HIGH

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-92531?

The SVN integration component of BugTracker.NET is vulnerable to an operating system command injection. This occurs when the application uses unvalidated input from the repository field in its svn.exe commands. An authenticated administrator could exploit this by inserting manipulated arguments into the database, which would then be executed during the revision comparison process. This risk emphasizes the need for proper input validation to prevent unauthorized command execution with application-level privileges, especially when svn.exe is installed and allowed to be called by the service.

Affected Version(s)

BugTracker.NET all versions

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Álvaro Monforte de la Huerga
Juan Gabriel Ruiz FernĂĄndez
.