Description
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process.
Published: 2026-09-17
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Apply Patch
AI Analysis

Impact

admin3 versions up to 3.0.0 allow authenticated users to upload files whose names are not sanitized. By including a path with dot‑dot segments, an attacker can place the file outside the configured storage directory on Windows systems. The resulting write can overwrite any file that the server process can access.

Affected Systems

The vulnerability exists in the admin3 project hosted by cjbi, affecting all releases through 3.0.0. It is relevant on Windows deployments where the server writes files to the local filesystem.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. Because exploitation requires authentication and only occurs on Windows, the practical attack surface is limited to users with upload capabilities. No evidence of available exploits is present; the EPSS score is not available and the issue is not listed in the CISA KEV catalog. Nevertheless, an attacker could overwrite configuration, webroot, or other critical files, potentially enabling remote code execution or data tampering.

Generated by OpenCVE AI on September 18, 2026 at 06:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a fixed release of admin3 if one is available; otherwise, contact the vendor for remediation details.
  • Restrict file upload functionality to administrators with strictly controlled inode permissions, and ensure the storage directory is not writable by external users.
  • Implement an input validation layer that rejects any filename containing '..' or absolute paths, and that resolves the final path to confirm it lies within the intended storage root.

Generated by OpenCVE AI on September 18, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cjbi
Cjbi admin3
Vendors & Products Cjbi
Cjbi admin3

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process.
Title admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:56.749Z

Reserved: 2026-09-17T11:07:29.772Z

Link: CVE-2026-92919

cve-icon Vulnrichment

Updated: 2026-09-17T18:42:03.365Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T13:17:01.173

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:33Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')