Unrestricted File Upload Vulnerability in BugTracker.NET by BugTracker.NET, Inc.
CVE-2026-92532
7.5HIGH
What is CVE-2026-92532?
An unrestricted file upload vulnerability exists in the attachment functionality of BugTracker.NET. This issue allows authenticated users with administrator privileges to manipulate the application configuration. By storing files in a web-accessible directory and lacking adequate file extension validation, an attacker can exploit this flaw to upload a malicious ASPX file. The successful execution of this file could lead to arbitrary code execution, compromising the security of the server with the privileges of the web service account.
Affected Version(s)
BugTracker.NET all versions
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ălvaro Monforte de la Huerga
Juan Gabriel Ruiz FernĂĄndez
