Skip to content
Multiple CVEs Disclosed for HUBzero and RosarioSIS CMS Vulnerabilities

Multiple CVEs Disclosed for HUBzero and RosarioSIS CMS Vulnerabilities

First seen 18 Sep 2026, 01:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • CVE-2026-92984 allows session hijacking via session fixation.
  • CVE-2026-92970 enables path traversal for file manipulation by authenticated users.
  • CVE-2026-93014 permits file deletion through path traversal in RosarioSIS.

On September 17, 2026, four critical vulnerabilities were published affecting HUBzero CMS and RosarioSIS. CVE-2026-92984 allows session fixation attacks, enabling unauthenticated attackers to hijack user sessions. CVE-2026-92970 exposes a path traversal vulnerability that could lead to unauthorized file creation and potential code execution by authenticated users. CVE-2026-93014 in RosarioSIS permits authenticated users to delete files via path traversal, risking data integrity. Lastly, CVE-2026-92980 in HortusFox-Web allows remote code execution by authenticated administrators through the Import/Export functionality. All vulnerabilities are classified as high priority for remediation due to their potential impact on sensitive data and system integrity. Current exploitation status remains unconfirmed for all CVEs, but they require immediate attention from affected organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
CVE-2026-92984 published
HUBzero CMS vulnerability allows session fixation attacks, risking account hijacking.
Redpacketsecurity
2026-09-17
CVE-2026-92970 published
Path traversal vulnerability in HUBzero CMS enables unauthorized file uploads and potential code execution.
Redpacketsecurity
2026-09-17
CVE-2026-93014 published
RosarioSIS vulnerability allows authenticated users to delete files via path traversal.
Redpacketsecurity
2026-09-17
CVE-2026-92980 published
HortusFox-Web vulnerability permits remote code execution through the Import/Export feature.
Redpacketsecurity

More articles in this cluster (6)

Following this threat?

Track CVE-2026-92970 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed