CVE-2026-92604
- Published16 Sept 2026
Description
Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path traversal sequences in the uploaded document's _id field to escape the intended directory and write files with .json extension to arbitrary locations as root.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HRemediation
No fixed version is recorded in the NVD data. Check the vendor advisory for the latest guidance.
References
- https://github.com/geo-chen/oss/blob/main/scirius.md
- https://github.com/StamusNetworks/scirius
- https://github.com/StamusNetworks/scirius/blob/3bb49d383f4801b79e6356f9de9f25806afe0311/suricata/rest_api.py#L105-L113
- https://www.vulncheck.com/advisories/scirius-through-3.8.0-arbitrary-file-write-via-pcap-upload
Related CVEs
Recent high-severity vulnerabilities sharing a weakness type.
Frequently asked
Is CVE-2026-92604 being actively exploited?
CVE-2026-92604 is not in the CISA KEV catalog.
How severe is CVE-2026-92604?
CVE-2026-92604 has a CVSS 3.1 base score of 8.1, rated high.
How do I fix CVE-2026-92604?
Apply the vendor's patch or advisory guidance, then verify no affected versions remain across your devices.
How Secuno handles this
Secuno correlates vulnerabilities like CVE-2026-92604 against the real software inventory on every managed device, every day. Rather than a static severity, each match is scored in context: exploit availability, EPSS, the asset's exposure, and business criticality decide where it lands in the queue. If an affected version is present anywhere across your portfolio, it surfaces automatically with a prioritised remediation path.
Data from the NVD, CISA KEV catalog and FIRST EPSS. CVSS 3.1 base score shown where available.