Vulnerability Description
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. This is fixed in 2.2.2 - 1103.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/limanmys/core/security/advisories/GHSA-3jrp-54r2-9g63
- https://github.com/limanmys/core/security/advisories/GHSA-3jrp-54r2-9g63
FAQ
What is CVE-2026-57499?
CVE-2026-57499 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execut...
How severe is CVE-2026-57499?
CVE-2026-57499 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-57499?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.