Back Redpacketsecurity CVE Alert: CVE-2026-92970 – hubzero – hubzero
HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution.
Treat as a high-priority remediation because a network-reachable, low-privilege account could potentially achieve server-level compromise without user interaction; KEV, SSVC exploitation status, EPSS and PoC indicators are not provided, so active exploitation cannot be confirmed.
Successful abuse could allow unauthorised file creation, website tampering, data theft, service disruption or follow-on malware deployment. The greatest concern is conversion of file-write capability into code execution under the web server account, particularly where the CMS host also contains credentials or internal connectivity.
### Most likely attack path
An attacker first obtains or abuses a legitimate project-member account, then sends crafted upload requests remotely; low attack complexity and no user interaction make exploitation practical once authenticated. Scope is unchanged, but compromise of the web server could still enable access to local secrets, databases and adjacent systems through available trust relationships.
### Who is most exposed
Internet-facing research, education or collaboration portals using project workspaces and member-upload functions are most exposed. Risk increases where membership is broadly granted, federated accounts are weakly governed, or the CMS shares a host with other services.
Alert on upload parameters containing traversal sequences, encoded separators or unexpected absolute paths.
Review web-server child-process creation and newly written executable or script files.
Hunt for writes outside the designated project storage directories.
Correlate unusual project-member logins with uploads, administrative actions and outbound connections.
### Mitigation and prioritisation
Apply the vendor’s security fixes promptly, with emergency change handling for internet-facing instances.
If patching is delayed, disable project uploads or affected APIs and restrict access through an authenticated gateway.
Enforce canonical-path validation, non-executable upload storage and least-privilege web-server permissions.
Rotate credentials and investigate hosts showing suspicious writes or post-upload process execution.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
