Arbitrary File Write Vulnerability in Scirius by Stamus Networks
CVE-2026-92604

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92604?

The Scirius application, in versions up to and including 3.8.0, contains a vulnerability that allows users with a default role to exploit the PCAP filestore upload endpoint. By manipulating the _id field in the uploaded JSON file, attackers can use path traversal sequences to escape the designated directory, leading to unauthorized file writes with .json extensions to arbitrary locations in the system. This flaw poses significant security risks, as it could allow malicious users to overwrite critical files or inject harmful content into the filesystem.

Affected Version(s)

scirius 0 <= 3.8.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.