PT-2026-78861 · Chenhg5+1 · Cc-Connect

·

CVE-2026-76761

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions chenhg5 cc-connect versions prior to 1.4.2
Description An OS command injection flaw exists in the Management API component within the shellExecCommand() function of the core/engine.go file. A remote attacker can exploit this by manipulating the exec argument to execute arbitrary operating system commands.
Recommendations Update chenhg5 cc-connect to version 1.4.2 or later. As a temporary mitigation, restrict access to the Management API or avoid using the shellExecCommand() function.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76761

Affected Products

Cc-Connect