PT-2026-94244 · Fatpipe · Mpvpn+2

·

CVE-2026-90822

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FatPipe MPVPN version 10.1.2r60p100 FatPipe WARP version 10.1.2r60p100 FatPipe IPVPN version 10.1.2r60p100
Description An OS command injection issue exists in the xtremed daemon. An unauthenticated remote attacker with access to the management interface can send crafted input to the 'AuthFormServlet' endpoint, which causes authentication data to be processed by a shell, allowing the execution of arbitrary commands with root privileges.
Recommendations Upgrade version 10.1.2r60p100 to a current supported release. Restrict management access to trusted administrative networks. Use WAN access control lists to limit access to trusted sources.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90822

Affected Products

Ipvpn
Mpvpn
Warp