CVE-2026-67599
Last modified
CVE-2026-67599 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webconfig user, and due to extensive NOPASSWD sudo privileges granted to that user by default, immediately escalate to root.. EPSS estimates a 1.91% chance of exploitation in the next 30 days.
Description
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webconfig user, and due to extensive NOPASSWD sudo privileges granted to that user by default, immediately escalate to root.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ClearFoundation | ClearOS | 7.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-67599?
How severe is CVE-2026-67599?
How do I fix CVE-2026-67599?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67591An authenticated attacker could exceed the session flow cont…6.5
- CVE-2026-67592It was not possible to govern the maximum number of transfer…7.5
- CVE-2026-67594Spikster through commit e1cdf8c contains a missing authentic…9.8
- CVE-2026-67595VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obf…9.2
- CVE-2026-67596CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contain…6.9
- CVE-2026-67598Emlog Pro through 2.6.23 contains a disabled TLS certificate…9.1
- CVE-2026-6760Mitigation bypass in the Networking: Cookies component. This…9.8
- CVE-2026-67607LightFTP 2.3.1 contains a residual race condition vulnerabil…8.2
- CVE-2026-67608Telenia Software TVox 26.5.3 and prior 26.x versions, and 24…8.6
- CVE-2026-67609Telenia Software TVox 26.5.3 and prior 26.x versions, and 24…8.5
- CVE-2026-6761Privilege escalation in the Networking component. This vulne…8.8
- CVE-2026-67610OpenEMR through 8.2.0 contains an improper authentication vu…8.1
Are you affected by CVE-2026-67599?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
