<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Empire (&lt; 6.7.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/empire--6.7.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:53:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/empire--6.7.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal in BC Security Empire Upload Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92748/</link><pubDate>Wed, 16 Sep 2026 21:53:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92748/</guid><description>BC Security Empire versions prior to 6.7.1 are vulnerable to path traversal via the multipart filename parameter, allowing an authenticated operator to achieve arbitrary file write and potential code execution.</description><content:encoded><![CDATA[<p>BC Security Empire versions before 6.7.1 contain a critical vulnerability in the handling of multipart filename parameters within the application's upload endpoints. This flaw allows an authenticated operator to perform path traversal attacks by injecting directory traversal sequences into the filename field during a file upload request. By successfully bypassing directory containment, an attacker can write arbitrary files to restricted locations on the underlying C2 server. This vulnerability is particularly severe because it provides a mechanism for an authenticated user to escalate privileges or achieve remote code execution by overwriting configuration files, web roots, or startup scripts on the server. Defenders should identify any anomalous file creation activity originating from authorized C2 operators and prioritize upgrading to version 6.7.1 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to achieve arbitrary file write capabilities on the C2 server. By writing to sensitive paths, an attacker can gain remote code execution, persist across system reboots, or modify server configuration to weaken security controls. Given that Empire is a Command and Control (C2) framework, compromising the server integrity undermines the security of the entire infrastructure managed by that server.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all BC Security Empire instances to version 6.7.1 or later immediately to patch CVE-2026-92748.</li>
<li>Audit logs for the upload endpoints to identify requests containing directory traversal patterns such as &quot;../&quot; or &quot;..\&quot; in multipart filename fields.</li>
<li>Review file system integrity on the C2 server for unexpected file modifications in system-critical or configuration directories.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>c2</category><category>path-traversal</category></item></channel></rss>