Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service. | |
| Title | Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET | |
| First Time appeared |
Bugtracker.net
Bugtracker.net bugtracker.net |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:bugtracker.net:bugtracker.net:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Bugtracker.net
Bugtracker.net bugtracker.net |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-10-07T10:48:41.717Z
Reserved: 2026-09-16T12:40:29.686Z
Link: CVE-2026-92531
No data.
Status : Received
Published: 2026-10-07T11:17:20.080
Modified: 2026-10-07T11:17:20.080
Link: CVE-2026-92531
No data.
OpenCVE Enrichment
Updated: 2026-10-07T12:30:16Z
Weaknesses