{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aadmin3admin3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:admin3:admin3:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92919"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["admin3 (\u003c= 3.0.0)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","web-vulnerability","windows","cve-2026-92919"],"_cs_type":"advisory","_cs_vendors":["admin3"],"content_html":"\u003cp\u003eCVE-2026-92919 describes a path traversal vulnerability in the admin3 application (all versions up to and including 3.0.0). The vulnerability resides in the file upload handler, which fails to adequately sanitize client-supplied filenames. When deployed on Windows systems, an authenticated user can provide filenames containing path traversal sequences, such as dot-dot (../ or ..), to break out of the designated storage root. This allows the attacker to write or overwrite files anywhere on the filesystem accessible to the user account running the admin3 process. If the attacker can write to executable directories or configuration files, this could lead to remote code execution or full system compromise. Defenders should prioritize auditing web server access logs for anomalous file upload requests containing path traversal characters and update to a patched version if available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to perform arbitrary file writes on the host system. This can lead to system-wide compromise, data loss, or the deployment of malicious binaries if the attacker can target sensitive application or system directories.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of admin3 running on Windows servers within the environment.\u003c/li\u003e\n\u003cli\u003eReview web application logs for POST requests to the file upload endpoint containing path traversal sequences (e.g., \u0026quot;../\u0026quot;, \u0026quot;..\\\u0026quot;).\u003c/li\u003e\n\u003cli\u003eRestrict access to the file upload functionality to trusted, authenticated users only.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized file creation or modification events in sensitive system directories, such as startup folders or application config paths, using EDR or file integrity monitoring.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T15:59:11Z","date_published":"2026-09-17T13:57:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92919/","summary":"The admin3 application through version 3.0.0 is vulnerable to path traversal, allowing authenticated attackers on Windows to overwrite arbitrary files via malicious filenames in the upload handler.","title":"Path Traversal in admin3 Upload Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92919/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:admin3:admin3:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}