ZeroHour

CVE-2026-92604

niche

Arbitrary File Write via Path Traversal in Stamus Networks Scirius ≤ 3.8.0

CVSS 4.0
7.2 high
EPSS
Published
()
Modified
AI analysis

Scirius through 3.8.0 contains an arbitrary file write flaw (CWE-22) in its PCAP filestore upload endpoint. An authenticated attacker holding only the default User role can embed path traversal sequences in an uploaded document's _id field, causing the server to escape the intended storage directory. The attacker-controlled JSON content is then written with a .json extension to arbitrary filesystem locations, and the write occurs with root privileges, giving the attacker high integrity and availability impact on the host (CVSS 4.0: 7.2 High, network-vector, low privileges required). Any organization running Scirius 3.8.0 or earlier, typically deployed to manage Suricata rulesets in SELKS or Stamus NSM environments, is affected. No public proof-of-concept is known, the issue is not in CISA KEV, and no exploitation has been reported to date.

What to do: Upgrade Scirius to a release newer than 3.8.0 as soon as a patched version is available from Stamus Networks. Until then, restrict User-role accounts in the Scirius UI to trusted operators, keep the console off the public internet, and audit the filesystem for unexpected .json files outside the PCAP filestore directory (especially in cron, systemd, or application config paths) to detect potential abuse.

Affected
Stamus Networks Sciriusthrough 3.8.0 (all versions up to and including 3.8.0)
Estimated exposure
nicheunknown — plausibly a few thousand NSM/SOC deployments at most — Scirius is a niche Suricata rule-management console bundled with SELKS/Stamus NSM deployments and has no public install metrics; it is typically deployed on internal monitoring networks rather than internet-facing, limiting plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path traversal sequences in the uploaded document's _id field to escape the intended directory and write files with .json extension to arbitrary locations as root.

Weakness
CWE-22
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.