---
id: CVE-2026-92532
title: >-
  Unrestricted file upload vulnerability in the BugTracker.NET attachment
  functionality
summary: >-
  Unrestricted file upload vulnerability in the BugTracker.NET attachment
  functionality. An authenticated user with administrator privileges could
  modify the application configuration to store files in a directory accessible
  via the web in…
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-434
vendor: BugTracker.NET
product: BugTracker.NET
affected:
  - BugTracker.NET all versions
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T11:17:20.287'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92532'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-bugtrackernet
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T11:26:47.656Z'
---

## Overview

Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could upload a malicious ASPX file and subsequently execute it on the server. A successful exploit could allow arbitrary code execution with the privileges of the account used by the web service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
