Path Traversal Vulnerability in BugTracker.NET by Interneer
CVE-2026-92533

7.1HIGH

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-92533?

A path traversal vulnerability exists within BugTracker.NET's file download component, allowing an authenticated remote attacker to exploit improper validation of user-supplied paths. By manipulating the file name parameter, an attacker may gain unauthorized access to files stored outside the designated directory. This could enable the attacker to read sensitive system files that are accessible to the user account executing the application, posing a significant security risk.

Affected Version(s)

BugTracker.NET all versions

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Álvaro Monforte de la Huerga
Juan Gabriel Ruiz FernĂĄndez
.