PT-2026-47150 · Unknown · Vertex-App

·

CVE-2026-11408

·

Published

2026-06-06

·

Updated

2026-06-07

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vertex-app vertex versions prior to 2026.02.12
Description An issue exists in the Log Viewer Endpoint component within the file app/model/LogMod.js. Improper processing of the req.query argument allows for remote OS command injection, which occurs when an attacker can execute arbitrary operating system commands on the server.
Recommendations Apply patch 805d82e7100d49b79b3beb1b9420e8e458987198 for versions prior to 2026.02.12.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11408

Affected Products

Vertex-App