---
id: CVE-2026-92748
title: >-
  BC Security Empire before 6.7.1 fails to validate the multipart filename
  parameter in upload endpoints, allowing authenticated operators to write files
  to arbitrary paths on the C2 server
summary: >-
  BC Security Empire before 6.7.1 fails to validate the multipart filename
  parameter in upload endpoints, allowing authenticated operators to write files
  to arbitrary paths on the C2 server. Attackers can use path traversal
  sequences in th…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: BC-SECURITY
product: Empire
affected:
  - Empire < 6.7.1
published: '2026-09-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:00:46.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92748'
references:
  - url: 'https://github.com/BC-SECURITY/Empire'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/BC-SECURITY/Empire/blob/v6.6.0/empire/server/core/download_service.py#L148-L193
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/BC-SECURITY/Empire/commit/c33a626316cb20bc8ed707e03a22d324d5d4762a
    label: disclosure@vulncheck.com
  - url: 'https://github.com/BC-SECURITY/Empire/issues/824'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/BC-SECURITY/Empire/releases/tag/v6.7.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/bc-security-empire-before-6.7.1-path-traversal-file-upload-rce
    label: disclosure@vulncheck.com
  - url: 'https://github.com/BC-SECURITY/Empire/issues/824'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00819
epssPercentile: 0.55356
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T18:24:56.862853Z'
ingestedAt: '2026-09-16T21:05:36.900Z'
---

## Overview

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive locations for code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
