EUVD Vulnerability Catalog

EUVD-2026-94283

Severity: HIGH Base Score: 7.5 CVSS Version: 4.0

Vulnerability Description

Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Attack Requirements (AT): Present
▪ Privileges Required (PR): High
▪ User Interaction (UI): None
▪ Vulnerability Confidentiality Impact (VC): High
▪ Vulnerability Integrity Impact (VI): High
▪ Vulnerability Availability Impact (VA): High
▪ Subsequent Confidentiality Impact (SC): None
▪ Subsequent Integrity Impact (SI): None
▪ Subsequent Availability Impact (SA): None

Affected Vendors & Systems

Vendor BugTracker.NET

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

INCIBE

EPSS Probability

0

Known Aliases
CVE-2026-92531
Published On

2026-10-07

Last Updated

2026-10-07