CVE-2026-89308

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 12:17

Updated : 2026-09-15 13:16


NVD link : CVE-2026-89308

Mitre link : CVE-2026-89308

CVE.ORG link : CVE-2026-89308


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')