CVE-2026-1427

Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wellchoose:single_sign-on_portal_system:*:*:*:*:*:*:*:*

History

11 Mar 2026, 22:51

Type Values Removed Values Added
References () https://www.twcert.org.tw/en/cp-139-10655-59160-2.html - () https://www.twcert.org.tw/en/cp-139-10655-59160-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10654-23f40-1.html - () https://www.twcert.org.tw/tw/cp-132-10654-23f40-1.html - Third Party Advisory
CPE cpe:2.3:a:wellchoose:single_sign-on_portal_system:*:*:*:*:*:*:*:*
First Time Wellchoose single Sign-on Portal System
Wellchoose
Summary
  • (es) El Sistema de Portal de Inicio de Sesión Único desarrollado por WellChoose tiene una vulnerabilidad de inyección de comandos del sistema operativo, permitiendo a atacantes remotos autenticados inyectar comandos arbitrarios del sistema operativo y ejecutarlos en el servidor.

26 Jan 2026, 09:15

Type Values Removed Values Added
Summary (en) Organization Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server. (en) Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

26 Jan 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 08:16

Updated : 2026-03-11 22:51


NVD link : CVE-2026-1427

Mitre link : CVE-2026-1427

CVE.ORG link : CVE-2026-1427


JSON object : View

Products Affected

wellchoose

  • single_sign-on_portal_system
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')