CVE-2026-92980: HortusFox-Web < 6.1 Remote Code Execution via Import/Export

Published Sep 17, 2026
·
Updated

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade HortusFox-Web to a version that resolves this vulnerability.

    Fixed in 6.1
  2. Compensating control

    Ensure only authenticated administrators can access HortusFox-Web Import/Export functionality until the update to 6.1 is applied.

Event History

Sep 17, 2026
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated administrator can exploit it. The attack requires access to the application's Import/Export functionality and does not require user interaction.

2

What level of access could an attacker obtain?

Successful exploitation allows arbitrary OS command execution as the web server user. This can affect the confidentiality, integrity, and availability of the underlying application server.

3

Are default deployments affected?

The provided information identifies HortusFox-Web versions prior to 6.1 as affected when an attacker can use the Import/Export feature. It does not state whether that feature is enabled or reachable in a default deployment.

4

What should be done if updating cannot happen immediately?

Restrict Import/Export access to only trusted administrators, since administrator access is required for exploitation. The provided information does not describe a separate workaround or configuration-based fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203