SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64881

HIGH · CVSS 8.8 EPSS 1.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability lies in the audit file upload handler, which fails to properly sanitize filenames, allowing shell metacharacters to be executed in system commands. This input validation flaw can lead to command injection attacks when combined with other related vulnerabilities. Organizations utilizing this affected upload handler should prioritize remediation to mitigate the risk of unauthorized command execution.

CVE
CVE-2026-64881
Severity
HIGH
CVSS
8.8
EPSS
1.44%

Original NVD Description

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)