CVE-2026-8153
CRITICALCVSS 9.8/10EPSS 1.83%
Last modified
CVE-2026-8153 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.. EPSS estimates a 1.83% chance of exploitation in the next 30 days.
Description
OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Universal Robots | PolyScope 5 | < 5.25.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-8153?
OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.
How severe is CVE-2026-8153?
CVE-2026-8153 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.83% probability of exploitation in the next 30 days.
How do I fix CVE-2026-8153?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81524A weakness in the MongoDB C Driver allows special elements i…5.4
- CVE-2026-81525The MongoDB client library for PHP does not sufficiently san…8.1
- CVE-2026-81526The MongoDB Rust Driver does not neutralize special characte…6.5
- CVE-2026-81527A NoSQL/expression injection weakness exists in the LINQ-to-…6.5
- CVE-2026-81528A MongoDB C# driver document-replacement code path omits the…5.4
- CVE-2026-81529Improper neutralization of delimiters in connection-URL cons…7.1
- CVE-2026-81530A weakness in the client-side encryption configuration surfa…5.6
- CVE-2026-81531An information disclosure vulnerability has been identified …6.9
- CVE-2026-81532A user able to submit SQL through an application using the M…8.8
- CVE-2026-81533An application using the MongoDB BI Connector ODBC Driver ma…7.1
- CVE-2026-81536IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a re…7.7
- CVE-2026-81537IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a re…8.8
Are you affected by CVE-2026-8153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
