SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64878

CRITICAL · CVSS 9.9 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Unvalidated input in asset filter parameters enables attackers to inject shell metacharacters, leading to remote code execution as a low-privileged OS user through the Analysis REST endpoint. Organizations utilizing affected products should prioritize patching this critical vulnerability to mitigate the risk of unauthorized access and potential system compromise. Immediate action is essential for any entity relying on the impacted systems to safeguard against exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64878
Severity
CRITICAL
CVSS
9.9
EPSS
0.54%

Original NVD Description

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

Related CVEs

Other vulnerabilities affecting the same vendor(s)