{"apiVersion":"1.0","identifier":"CVE-2026-57499","description":"Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. This is fixed in 2.2.2 - 1103.","publishedAt":"2026-08-27T17:18:52","lastModifiedAt":"2026-08-27T20:17:51","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57499","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00958,"riskScore":0.99,"affectedProduct":"Liman","affectedVersions":"<2.2.2-1103","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-57499","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-57499","en":"https://www.redsauce.net/en/cves/CVE-2026-57499","fr":"https://www.redsauce.net/fr/cves/CVE-2026-57499","pt":"https://www.redsauce.net/pt/cves/CVE-2026-57499","de":"https://www.redsauce.net/de/cves/CVE-2026-57499","sk":"https://www.redsauce.net/sk/cves/CVE-2026-57499","el":"https://www.redsauce.net/el/cves/CVE-2026-57499"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-57499"}}