Remote Code Execution in HortusFox-Web Affects Servers
CVE-2026-92980
8.6HIGH
What is CVE-2026-92980?
HortusFox-Web, prior to version 6.1, contains a vulnerability that allows authenticated administrators to execute arbitrary operating system commands on the web server. This can be accomplished by exploiting the Import/Export functionality, which was designed for data portability but can be abused by attackers to deploy and execute malicious code on the underlying server. Therefore, administrators are advised to upgrade to version 6.1 or later to mitigate this security risk.
Affected Version(s)
hortusfox-web 0 < 6.1
