CVE-2026-92980: HortusFox-Web < 6.1 Remote Code Execution via Import/Export
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HortusFox-Webto a version that resolves this vulnerability.Fixed in 6.1 - Compensating control
Ensure only authenticated administrators can access HortusFox-Web Import/Export functionality until the update to 6.1 is applied.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated administrator can exploit it. The attack requires access to the application's Import/Export functionality and does not require user interaction.
What level of access could an attacker obtain?
Successful exploitation allows arbitrary OS command execution as the web server user. This can affect the confidentiality, integrity, and availability of the underlying application server.
Are default deployments affected?
The provided information identifies HortusFox-Web versions prior to 6.1 as affected when an attacker can use the Import/Export feature. It does not state whether that feature is enabled or reachable in a default deployment.
What should be done if updating cannot happen immediately?
Restrict Import/Export access to only trusted administrators, since administrator access is required for exploitation. The provided information does not describe a separate workaround or configuration-based fix.