Description
BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive locations for code execution.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

BC Security Empire prior to version 6.7.1 allows authenticated operators to upload files without validating the multipart filename parameter. The lack of validation permits path traversal sequences, enabling an attacker to place files in arbitrary directories on the C2 server. By writing malicious files to privileged locations, an attacker can achieve code execution on the server, compromising confidentiality, integrity, and availability of the system.

Affected Systems

The vulnerability impacts BC Security Empire deployments running any release before 6.7.1. This includes all users of the standard C2 server where operators hold authentication credentials and have upload permissions.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as a high‑severity issue. The EPSS score is below 1%, indicating a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KE be authenticated operators with access to the upload endpoint; the path traversal in the filename is the primary attack vector, allowing arbitrary file writes that can lead to remote code execution if the attacker can deploy executable payloads.

Generated by OpenCVE AI on September 18, 2026 at 06:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade BC Security Empire to version 6.7.1 or later, where the multipart filename validation issue is fixed.
  • If an upgrade cannot be performed immediately, disable or tightly restrict the upload endpoints for operators until a patch is applied, and enforce network ACLs or firewall rules to block unauthorized upload attempts.
  • Implement additional server-side validation to ensure uploaded filenames are sanitized, prevent path traversal, and limit uploads to a safe, designated directory dedicated for binary payloads via configuration or a custom upload handler.

Generated by OpenCVE AI on September 18, 2026 at 06:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Bcsecurity
Bcsecurity empire
Vendors & Products Bcsecurity
Bcsecurity empire
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive locations for code execution.
Title BC Security Empire before 6.7.1 Path Traversal File Upload RCE
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Bcsecurity Empire
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:25:40.047Z

Reserved: 2026-09-16T18:57:07.057Z

Link: CVE-2026-92748

cve-icon Vulnrichment

Updated: 2026-09-18T18:25:32.096Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:23.387

Modified: 2026-09-24T21:00:46.893

Link: CVE-2026-92748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')