Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege. (CVE-2026-21092)
A path traversal vulnerability exists in ImsService prior to SMR Sep-2026 Release 1 that allows remote attackers to create image files with system server privileges. This vulnerability could enable unauthorized file creation at privileged locations. No patch information is provided, and no known exploits are reported in the wild.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-21092 involves a path traversal flaw in ImsService versions before SMR Sep-2026 Release 1. This flaw permits remote attackers to create image files with system server privileges, potentially leading to unauthorized file manipulation at a high privilege level. The vulnerability has been assigned a high severity rating. There is no explicit patch or remediation information available in the provided data.
Potential Impact
Remote attackers can exploit this path traversal vulnerability to create image files with system server privileges, which may lead to unauthorized file creation and potential system compromise. The high severity rating indicates significant risk if exploited, but no active exploitation is currently known.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch information is provided, users should monitor vendor communications for updates and apply the SMR Sep-2026 Release 1 or later once available.
Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege. (CVE-2026-21092)
Description
A path traversal vulnerability exists in ImsService prior to SMR Sep-2026 Release 1 that allows remote attackers to create image files with system server privileges. This vulnerability could enable unauthorized file creation at privileged locations. No patch information is provided, and no known exploits are reported in the wild.
CVSS v4.0
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-21092 involves a path traversal flaw in ImsService versions before SMR Sep-2026 Release 1. This flaw permits remote attackers to create image files with system server privileges, potentially leading to unauthorized file manipulation at a high privilege level. The vulnerability has been assigned a high severity rating. There is no explicit patch or remediation information available in the provided data.
Potential Impact
Remote attackers can exploit this path traversal vulnerability to create image files with system server privileges, which may lead to unauthorized file creation and potential system compromise. The high severity rating indicates significant risk if exploited, but no active exploitation is currently known.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch information is provided, users should monitor vendor communications for updates and apply the SMR Sep-2026 Release 1 or later once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-g985-cfxj-6q8r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-21092"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6aa15f7cacd9273b49618394
Added to database: 09/09/2026, 13:30:36 UTC
Last enriched: 09/09/2026, 13:57:59 UTC
Last updated: 09/10/2026, 03:00:35 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.