PatchSiren

BugTracker.NET CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH BugTracker.NET CVE published 2026-10-07

CVE-2026-92532

CVE-2026-92532: Unrestricted Upload of File with Dangerous Type in BugTracker.NET allows an authenticated administrator to upload malicious ASPX files, potentially leading to arbitrary code execution with the privileges of the web service account. This vulnerability exists in the BugTracker.NET attachment functionality, where administrators can modify application configurations to store files in a web-acc [truncated]