CVE-2026-90770

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-13 11:17

Updated : 2026-09-13 11:17


NVD link : CVE-2026-90770

Mitre link : CVE-2026-90770

CVE.ORG link : CVE-2026-90770


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')