CVE-2026-92919: admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename

Published Sep 17, 2026
·
Updated

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process.

Affected Software

1 affected component
admin3>=0<3.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade admin3 to a version that resolves this vulnerability.

    Fixed in 3.0.0
  2. Configuration

    Update the upload handler’s filename sanitization so that dot-dot path segments in uploaded filenames cannot escape the configured storage root.

    admin3 upload handler filename sanitization = sanitize client-supplied filenames to prevent dot-dot (.. ) path traversal from escaping the configured storage directory

Event History

Sep 17, 2026
CVE Published
via MITRE·12:33 PM
Data Sourced
via MITRE·12:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an authenticated admin3 account with access to the upload handler. Exploitation is limited to Windows deployments.

2

What level of access does an attacker gain through the file write?

The attacker can overwrite files outside the configured storage directory, but only files that are accessible to the server process. Successful exploitation can affect integrity and availability.

3

How can I determine whether a deployment is exposed?

A deployment is exposed if it runs admin3 through version 3.0.0 on Windows and permits authenticated users to upload files through the affected upload handler. Review upload activity for filenames containing dot-dot path segments, which are used to escape the storage directory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203