CVE-2026-3065
MEDIUMHummerRisk <1.5.0 - Command Injection
Title source: llmDescription
A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the component Cloud Task Dry-run. Performing a manipulation of the argument fileName results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scores
CVSS v3
6.3
EPSS
0.0041
EPSS Percentile
60.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-77
Status
published
Affected Products (1)
hummerrisk/hummerrisk
< 1.5.0
Timeline
Published
Feb 24, 2026
Tracked Since
Feb 24, 2026