CVE-2026-38945

Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.
Configurations

No configuration.

History

01 Jun 2026, 17:16

Type Values Removed Values Added
References
  • () https://support.raynet.de/hc/en-us/articles/46163206384788-RSEC200967-Java-Detection-Path-Traversal -

27 May 2026, 19:16

Type Values Removed Values Added
Summary (en) Command injection in Raynet rvia version 12.6.4392.49-amd64.deb allows adversaries to execute arbitrary Java code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command. (en) Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.

27 May 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References
  • () https://github.com/Wise-Security/CVE-2026-38945/blob/main/CVE-2026-38945.sh -
CWE CWE-77

27 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 17:16

Updated : 2026-06-01 18:12


NVD link : CVE-2026-38945

Mitre link : CVE-2026-38945

CVE.ORG link : CVE-2026-38945


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')