CVE-2026-2731Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-20: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 102-1902-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-201
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2731 Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (&lt;9.19.7 and &lt;9.20.3) allows unauthenticated attackers to execute code via … https://www.cve.org/CVERecord?id=CVE-2026-2731

    Post summary

    The CVE‑2026‑2731 vulnerability involves path traversal and content injection in DynamicWeb’s JobRunnerBackground.aspx, allowing unauthenticated attackers to execute code, with technical details disclosed but no PoC, exploit, patch, or active exploitation reported.

    01001151
    56.4K followersView on X
  • Sami Laiho@samilaiho
    General

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')  in DynamicWeb DynamicWeb 9 URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2731 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0

    Post summary

    The NVD entry reports CVE-2026-2731 as a critical path traversal flaw in DynamicWeb 9 with no PoC, exploit details, or patch information provided in the text.

    00010361
    30.4K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-2731: Unauthenticated RCE in Dynamicweb... Trivial JobRunnerBackground.aspx path traversal leads to full system compromise via direct HTTP requests - no auth neede... https://zerodaysignal.com/vulnerability/CVE-2026-2731 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-2731 is an unauthenticated remote code execution vulnerability in Dynamicweb's JobRunnerBackground.aspx, allowing full system compromise through direct HTTP requests. No exploit code, patch, or active exploitation evidence is provided.

    0000061
    131 followersView on X

Explore more