CVE-2026-2731: Dynamicweb 9

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests

Affected products

  • Dynamicweb Dynamicweb 9: version 8 only; from 9, before 9.19.7 (fixed in 9.19.7); from 9.20.0, before 9.20.3 (fixed in 9.20.3)

Published 2026-02-19. Last modified 2026-06-17.