Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service. | |
| Title | Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET | |
| First Time appeared |
Bugtracker.net
Bugtracker.net bugtracker.net |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:bugtracker.net:bugtracker.net:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Bugtracker.net
Bugtracker.net bugtracker.net |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-10-07T14:52:05.056Z
Reserved: 2026-09-16T12:40:29.686Z
Link: CVE-2026-92531
No data.
Status : Deferred
Published: 2026-10-07T11:17:20.080
Modified: 2026-10-07T14:47:35.590
Link: CVE-2026-92531
No data.
OpenCVE Enrichment
Updated: 2026-10-07T12:45:16Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')