PT-2026-71367 · Upsnap · Upsnap

CVE-2026-49481

·

Published

2026-08-12

·

Updated

2026-08-13

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions UpSnap versions prior to 5.4.0
Description An OS command injection flaw exists in the device management functionality. This occurs due to unsafe shell command template interpolation using the ip and mac fields. An authenticated low-privileged user with permissions to create or edit devices can insert controlled values into the wake cmd and shutdown cmd templates. These values are executed via /bin/sh -c on Linux or cmd /C on Windows without proper sanitization, leading to Remote Code Execution (RCE) on the hosted server.
Recommendations Update to version 5.4.0.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49481
GHSA-6MC7-6948-W5H4

Affected Products

Upsnap