CVE-2026-92748: BC Security Empire before 6.7.1 Path Traversal File Upload RCE

Published Sep 16, 2026
·
Updated

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive locations for code execution.

Affected Software

1 affected component
BC Security Empire<6.7.1

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Empire operator can exploit it. The attack is network-accessible and requires low privileges, but no user interaction.

2

Are default deployments affected?

The provided information identifies affected upload endpoints but does not state whether they are enabled or reachable in a default deployment. Any deployment that allows operator access to those endpoints should be considered exposed until updated.

3

What should be done if an immediate upgrade is not possible?

Restrict operator access to trusted users and limit network access to the Empire server and its upload endpoints. Monitor for upload requests containing path traversal sequences in multipart filenames and investigate unexpected files written outside intended upload locations.

4

How can administrators check for possible compromise?

Review server files for unexpected or recently created files in sensitive locations outside intended upload directories. Review upload-related logs, if available, for authenticated operator requests with traversal sequences in filename parameters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203