← Retour à la recherche de CVE

CVE-2026-64879

Unknown

Description

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

CVSS 9.9EPSS 2.59%Risque 1.22
Voir la source
Publication
2026-07-21 20:17:04
Versions concernées
unknown
Type
Application web
Dernière modification
2026-07-24 05:16:48
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H