PatchSiren cyber security CVE debrief
CVE-2026-92748 BC-SECURITY CVE debrief
CVE-2026-92748 is a high-severity vulnerability in BC Security Empire before version 6.7.1. The vulnerability allows authenticated operators to write files to arbitrary paths on the C2 server due to improper validation of the multipart filename parameter in upload endpoints. This can be exploited using path traversal sequences to bypass directory containment and write malicious files to sensitive locations, potentially leading to code execution.
- Vendor
- BC-SECURITY
- Product
- Empire
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-18
Who should care
Defenders and security teams responsible for BC Security Empire instances, especially those with authenticated operator access, should assess exposure and prioritize patching or mitigation efforts.
Why it matters
CVE-2026-92748 is a high-severity vulnerability in BC Security Empire that allows authenticated operators to write files to arbitrary paths on the C2 server, potentially leading to code execution. Defenders should prioritize patching or mitigating this vulnerability, especially in environments where authenticated operator access is possible. The vulnerability's impact is amplified by its high CVSS score of 8.7 and the potential for code execution. However, specific details about exploitation or affected versions beyond 'before 6.7.1' are limited, requiring verification from official sources.
- Potential code execution on the C2 server
- Arbitrary file writing to sensitive locations
- Bypassing of directory containment using path traversal sequences
- Possible lateral movement or escalation of privileges
Technical summary
The BC Security Empire server fails to properly validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the server. This can be exploited using path traversal sequences to bypass directory containment and write malicious files to sensitive locations, potentially leading to code execution. Defenders should prioritize patching or mitigating this vulnerability, especially in environments where authenticated operator access is possible. The vulnerability's impact is amplified by its high CVSS score of 8.7 and the potential for code execution.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially in environments where authenticated operator access is possible.
Recommended defensive actions
- Assess exposure and prioritize patching for BC Security Empire instances before version 6.7.1
- Implement compensating controls to restrict file uploads and monitor for suspicious activity
- Verify operator access controls and limit authenticated user privileges
- Review and update incident response plans to address potential code execution risks
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its high CVSS score of 8.7 and the potential for code execution. However, specific details about exploitation or affected versions beyond 'before 6.7.1' are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92748 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92748
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92748 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92748
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/BC-SECURITY/Empire
-
Source reference
Unverified legacy reference
URL: https://github.com/BC-SECURITY/Empire/blob/v6.6.0/empire/server/core/download_service.py
-
Source reference
Unverified legacy reference
URL: https://github.com/BC-SECURITY/Empire/commit/c33a626316cb20bc8ed707e03a22d324d5d4762a
-
Source reference
Unverified legacy reference
URL: https://github.com/BC-SECURITY/Empire/issues/824
-
Source reference
Unverified legacy reference
URL: https://github.com/BC-SECURITY/Empire/releases/tag/v6.7.1
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/bc-security-empire-before-6.7.1-path-traversal-file-upload-rce
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.