CVE-2026-92532: Bugtracker.net

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could upload a malicious ASPX file and subsequently execute it on the server. A successful exploit could allow arbitrary code execution with the privileges of the account used by the web service.

Affected products

Published 2026-10-07. Last modified 2026-10-07.