Clearos · Clearos · CVE-2026-67599
**Name of the Vulnerable Software and Affected Versions**
ClearOS version 7.9
**Description**
The Log Viewer component contains an OS command injection flaw. Authenticated attackers can execute arbitrary commands by submitting unsanitized input through the `filter` parameter, which is interpolated directly into a shell command within File.php. By using command substitution payloads in the `filter` parameter, attackers can execute commands as the webconfig user and subsequently escalate privileges to root due to default NOPASSWD sudo permissions granted to that user.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.