Vulnerability Description
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-90444?
CVE-2026-90444 is a documented vulnerability. A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system comman...
How severe is CVE-2026-90444?
CVSS scoring is not yet available for CVE-2026-90444. Check NVD for updates.
Is there a patch for CVE-2026-90444?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.