CVE-2026-92748

HIGH CVSS 4.0: 8.7 EPSS 0.66%
Updated Sep 18, 2026
BC
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions before 6.7.1
Type CWE-22 (Path Traversal)
Vendor BC
Public PoC No

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive locations for code execution.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)