HIGH
BC-SECURITY
CVE published 2026-09-16
CVE-2026-92748
CVE-2026-92748 is a high-severity vulnerability in BC Security Empire before version 6.7.1. The vulnerability allows authenticated operators to write files to arbitrary paths on the C2 server due to improper validation of the multipart filename parameter in upload endpoints. This can be exploited using path traversal sequences to bypass directory containment and write malicious files to sensitive location [truncated]