CVE-2026-9717
Last modified
CVE-2026-9717 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Powerlogic P7 Firmware | < 02.004.001.000 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9717?
How severe is CVE-2026-9717?
How do I fix CVE-2026-9717?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9716CWE-476 NULL Pointer Dereference vulnerability exists that c…7.5
- CVE-2026-97160Joomla Extension - lomart.fr - Authenticated, privileged PHP…9.4
- CVE-2026-97161Joomla Extension - lomart.fr - Various path traversal / file…9.2
- CVE-2026-97162Joomla Extension - lomart.fr - Various SQL injection vectors…8.3
- CVE-2026-97163Joomla Extension - lomart.fr - Unauthenticated remote code i…10
- CVE-2026-97168Rejected reason: it is a suggestion
- CVE-2026-97176A flaw was found in the Level of Authentication enforcement …4.2
- CVE-2026-97177A flaw was found in the user update mechanism of the Keycloa…6.6
- CVE-2026-97179A security vulnerability has been detected in O2OA up to 9.5…4.3
- CVE-2026-9718CWE-617 Reachable Assertion vulnerability exists that could …6.5
- CVE-2026-97181GPM LIGHT developed by ezGlobal has a Sensitive Data Exposur…5.3
- CVE-2026-97182A security vulnerability has been detected in halo-dev Halo …7.3
Are you affected by CVE-2026-9717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
