Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/research/tra-2026-46 |
Configurations
No configuration.
History
28 May 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 21:16
Updated : 2026-06-01 18:12
NVD link : CVE-2026-9645
Mitre link : CVE-2026-9645
CVE.ORG link : CVE-2026-9645
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
