{"id":"CVE-2026-92980","title":"HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality","summary":"HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can …","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"danielbrendel","product":"hortusfox-web","affected":["hortusfox-web < 6.1"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:18:17.280","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92980","references":[{"url":"https://github.com/danielbrendel/hortusfox-web/commit/1c7108f23fa30759d6f3bf62f0cfbf975bdc0a3b","label":"disclosure@vulncheck.com"},{"url":"https://github.com/danielbrendel/hortusfox-web/releases/tag/v6.1","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hortusfox-web-remote-code-execution-via-import-export","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T18:07:28.291929Z"},"epss":0.00531,"epssPercentile":0.43664,"ingestedAt":"2026-09-17T16:21:47.905Z","slug":"CVE-2026-92980","body":"## Overview\n\nHortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}