CVE-2026-92533EPSS p28.1%
CVE-2026-92533CVE-2026-92533
Description
Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to access files located outside the intended directory. Successful exploitation could allow the attacker to read system files accessible to the account used by the application.
Scoring
| EPSS | 0.36% probability of exploitation · percentile 28.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |