{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hubzero-cms--2.2.32/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hubzero:hubzero_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92970"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HUBzero CMS (\u003c= 2.2.32)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve-2026-92970","path-traversal","web-application","session-fixation","authentication"],"_cs_type":"advisory","_cs_vendors":["HUBzero"],"content_html":"\u003cp\u003eHUBzero CMS versions up to and including 2.2.32 are vulnerable to a path traversal flaw within their project file upload handlers. An authenticated project member can craft malicious input containing directory traversal sequences (e.g., ../) within the upload parameters. When processed by the application, these sequences allow the user to bypass intended storage constraints and write files to arbitrary locations on the underlying host filesystem. Because the application performs these operations with the privileges of the web server process, this vulnerability can be leveraged to place malicious scripts or configuration files into executable directories, facilitating remote code execution. Given the impact on system integrity and the potential for full server compromise, organizations running affected versions should prioritize mitigation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to gain arbitrary file write access to the host server. This can lead to full system compromise if an attacker is able to overwrite critical configuration files or upload web shells to reachable web directories. The vulnerability affects all deployments of HUBzero CMS version 2.2.32 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading to a patched version of HUBzero CMS once the vendor releases a security update addressing CVE-2026-92970. Until a patch is applied, implement strict access controls for project file management, restrict user upload privileges, and monitor web server logs for suspicious POST requests containing directory traversal sequences in file upload parameters.\u003c/p\u003e\n\u003ch2 id=\"rules\"\u003eRules\u003c/h2\u003e\n\u003cp\u003etitle: \u0026quot;Detect Path Traversal Attempt in HUBzero CMS File Upload\u0026quot;\ndescription: \u0026quot;Detects potential path traversal exploitation targeting CVE-2026-92970 by identifying directory traversal sequences in file upload parameters.\u0026quot;\nlogsource:\ncategory: \u0026quot;webserver\u0026quot;\ndetection:\nselection:\ncs-method: \u0026quot;POST\u0026quot;\ncs-uri-stem|contains: \u0026quot;/project/upload\u0026quot;\ncs-uri-query|contains:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u0026quot;../\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;..\\\u0026quot;\nfilter:\nsc-status|startswith: \u0026quot;4\u0026quot;\ncondition: selection and not filter\nlevel: \u0026quot;high\u0026quot;\ntags:\u003c/li\u003e\n\u003cli\u003e\u0026quot;attack.initial_access\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;attack.execution\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;attack.t1505.002\u0026quot;\nfalsepositives:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Legitimate administrative tools or plugins that use traversal sequences for folder navigation\u0026quot;\ntests:\npositive:\u003c/li\u003e\n\u003cli\u003ename: \u0026quot;Upload request containing path traversal sequence\u0026quot;\ndata:\u003c/li\u003e\n\u003cli\u003ecs-method: \u0026quot;POST\u0026quot;\ncs-uri-stem: \u0026quot;/project/upload\u0026quot;\ncs-uri-query: \u0026quot;filename=../../etc/passwd\u0026quot;\nsc-status: \u0026quot;200\u0026quot;\nnegative:\u003c/li\u003e\n\u003cli\u003ename: \u0026quot;Standard file upload\u0026quot;\ndata:\u003c/li\u003e\n\u003cli\u003ecs-method: \u0026quot;POST\u0026quot;\ncs-uri-stem: \u0026quot;/project/upload\u0026quot;\ncs-uri-query: \u0026quot;filename=data.csv\u0026quot;\nsc-status: \u0026quot;200\u0026quot;\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T16:00:17Z","date_published":"2026-09-17T15:59:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hubzero-path-traversal/","summary":"Authenticated users can exploit a path traversal vulnerability in HUBzero CMS project file upload handlers to achieve arbitrary file writes, potentially leading to remote code execution.","title":"Path Traversal Vulnerability in HUBzero CMS","url":"https://feed.craftedsignal.io/briefs/2026-09-hubzero-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - HUBzero CMS (\u003c= 2.2.32)","version":"https://jsonfeed.org/version/1.1"}