PT-2026-67488 · Clearos · Clearos

·

CVE-2026-67599

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClearOS version 7.9
Description The Log Viewer component contains an OS command injection flaw. Authenticated attackers can execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command within File.php. By using command substitution payloads in the filter parameter, attackers can execute commands as the webconfig user and subsequently escalate privileges to root due to default NOPASSWD sudo permissions granted to that user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67599

Affected Products

Clearos