← לוח פגיעויות

CVE-2026-64879

קריטית 9.9

תיאור (מקור, אנגלית)

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

מדדים

CVSS 3.1
9.9 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 4.0
9.4 (CRITICAL) מקור הציון: CNA CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
3% (אחוזון 100) נכון ל-1/8/2026
CWE
CWE-78

קישורים