SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-21092

MEDIUM · CVSS 5.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

ImsService prior to the September 2026 Release 1 is vulnerable to a path traversal flaw that enables remote attackers to create image files with system server privileges. This could lead to unauthorized access and potential system compromise. Organizations utilizing affected versions of ImsService should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-21092
Severity
MEDIUM
CVSS
5.3
EPSS
0.32%

Original NVD Description

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

Related CVEs

Other vulnerabilities affecting the same vendor(s)