Description
HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Write with potential code execution
Action: Immediate Patch
AI Analysis

Impact

HUBzero CMS through version 2.2.32 is vulnerable to a path traversal flaw in the project file upload process. The flaw allows an authenticated project member to supply traversal sequences in the upload parameters that cause the server to write files outside the intended project repository. If the attacker can place executable scripts or web shell components, the vulnerability could lead to remote code execution with web‑server privileges.

Affected Systems

All installations of HUBzero CMS up to and including version 2.2.32 are affected. The bug resides in the file upload handlers located in the core components and plugin connections. Users should check the vendor’s release notes for the fixed version.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating a high severity level. EPSS information is not available, but the path traversal flaw can be abused by users with legitimate project membership. Since the code runs with web‑server privileges, the potential for damaging or total compromise is significant. The issue is not listed in the CISA KEV catalog, yet the high impact warrants urgent attention.

Generated by OpenCVE AI on September 18, 2026 at 00:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the patched release of HUBzero CMS (version 2.2.33 or later).
  • Restrict project member permissions to prevent file uploads to repository directories, or disable the upload feature for non‑trusted users.
  • Implement input validation on the file upload parameters to strip traversal sequences before the file is written.

Generated by OpenCVE AI on September 18, 2026 at 00:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hubzero
Hubzero hubzero-cms
Vendors & Products Hubzero
Hubzero hubzero-cms

Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to attacker-chosen paths with web server privileges, potentially enabling code execution.
Title HUBzero CMS through 2.2.32 Path Traversal via File Upload
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hubzero Hubzero-cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:25:58.242Z

Reserved: 2026-09-17T13:23:50.419Z

Link: CVE-2026-92970

cve-icon Vulnrichment

Updated: 2026-09-19T02:25:53.879Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:18:02.997

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')