CVE-2026-82804
Published 29 September 2026 · tracked since 30 September 2026
Description
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution.An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97395
- CVE-2026-71898 MEDIUM 4.3
- CVE-2026-71899
- CVE-2026-78214 MEDIUM 5.3
- CVE-2026-81569 MEDIUM 4.3
- CVE-2026-71897 MEDIUM 4.3
- CVE-2026-98164
- CVE-2026-82973 CRITICAL 9.4
- CVE-2026-73599 MEDIUM 5.4
- CVE-2026-100823