CVE-2026-71376
Last modified
CVE-2026-71376 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18..
Description
OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Component Container | >= 11-70-01, < 11-70-03; >= 11-60, < 11-60-03; >= 11-50, <= 11-50-03; >= 11-40, <= 11-40-03; >= 11-30, <= 11-30-08; >= 11-20, < 11-20-10; >= 11-10, <= 11-10-11; >= 11-00, < 11-00-13; >= 09-87, < 09-87-10; >= 09-80, < 09-80-05; >= 09-70, < 09-70-28; >= 09-50, <= 09-50-22; >= 09-00, <= 09-00-18 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-71376?
How severe is CVE-2026-71376?
How do I fix CVE-2026-71376?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71365A server-side request forgery (SSRF) vulnerability was found…7.7
- CVE-2026-71366A server-side request forgery (SSRF) vulnerability was found…7.7
- CVE-2026-71368F-RevoCRM contains a cross-site scripting vulnerability. If …5.1
- CVE-2026-7137A security vulnerability has been detected in Totolink A8000…9.8
- CVE-2026-71374Deserialization of untrusted data vulnerability in Cosminexu…9.8
- CVE-2026-71375Improper restriction of XML external entity reference vulner…7.4
- CVE-2026-71377Command Argument Injection Vulnerability in Cosminexus Compo…9.8
- CVE-2026-71378ResourceIsolationRequestCycleListener protects a Wicket appl…4.6
- CVE-2026-7138A vulnerability was detected in Totolink A8000RU 7.1cu.643_b…9.8
- CVE-2026-71380Missing Release of Resource after Effective Lifetime vulnera…8.7
- CVE-2026-71381Adobe Genuine Software Integrity Service on Windows is affec…4
- CVE-2026-71382Substance3D - Sampler is affected by an out-of-bounds write …7.8
Are you affected by CVE-2026-71376?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
