High severity7.2NVD Advisory· Published Sep 17, 2026
CVE-2026-92980
CVE-2026-92980
Description
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.