{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/scirius--3.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:scirius:scirius:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92604"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Scirius (\u003c= 3.8.0)"],"_cs_severities":["high"],"_cs_tags":["arbitrary-file-write","path-traversal","web-application"],"_cs_type":"advisory","_cs_vendors":["Scirius"],"content_html":"\u003cp\u003eScirius versions through 3.8.0 contain a critical vulnerability in the PCAP filestore upload endpoint that permits arbitrary file writes. The flaw originates from insufficient sanitization of the _id field within uploaded JSON documents processed by the endpoint. Authenticated users assigned the default User role can exploit this by injecting path traversal sequences (such as ../) into the _id field. This manipulation allows the application to write attacker-controlled JSON content to arbitrary locations on the host filesystem. Because the application processes these requests with root privileges, this vulnerability enables the creation of malicious files with a .json extension in protected directories, potentially facilitating further exploitation such as configuration manipulation or code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated low-privileged users to achieve arbitrary file writes with root privileges. This can lead to full system compromise, persistent unauthorized access, or the overwriting of critical system configuration files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Scirius to a patched version beyond 3.8.0 as soon as the vendor makes a fix available.\u003c/li\u003e\n\u003cli\u003eAudit logs for the PCAP filestore upload endpoint for requests containing path traversal characters (e.g., ../) in the _id field.\u003c/li\u003e\n\u003cli\u003eRestrict access to the PCAP filestore upload functionality to only authorized administrative accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T19:51:59Z","date_published":"2026-09-16T19:51:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-scirius-arbitrary-file-write/","summary":"Scirius versions 3.8.0 and earlier are vulnerable to an arbitrary file write attack via the PCAP filestore upload endpoint, allowing authenticated users to perform path traversal to write files to arbitrary locations.","title":"Arbitrary File Write in Scirius PCAP Filestore Upload","url":"https://feed.craftedsignal.io/briefs/2026-09-scirius-arbitrary-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - Scirius (\u003c= 3.8.0)","version":"https://jsonfeed.org/version/1.1"}