SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-59561

HIGH · CVSS 7.8 EPSS 0.74% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Sakura Editor contains an OS command injection vulnerability that allows arbitrary command execution on a user's system when they open a terminal from a specially crafted directory. This high-severity flaw poses significant risks to users who may inadvertently execute malicious commands, making it critical for all users of Sakura Editor to prioritize updates and mitigate exposure. Organizations and individuals relying on this software should take immediate action to secure their environments against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59561
Severity
HIGH
CVSS
7.8
EPSS
0.74%

Original NVD Description

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".