PatchSiren

BC-SECURITY CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH BC-SECURITY CVE published 2026-09-16

CVE-2026-92748

CVE-2026-92748 is a high-severity vulnerability in BC Security Empire before version 6.7.1. The vulnerability allows authenticated operators to write files to arbitrary paths on the C2 server due to improper validation of the multipart filename parameter in upload endpoints. This can be exploited using path traversal sequences to bypass directory containment and write malicious files to sensitive location [truncated]