CVE-2026-39052

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restrictions.
Configurations

No configuration.

History

15 May 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-94

15 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 15:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-39052

Mitre link : CVE-2026-39052

CVE.ORG link : CVE-2026-39052


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')