CVE-2026-3120

HIGH

RCE in Profelis Informatics' SambaBox

Title source: cna
STIX 2.1

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.

References (2)

Core 2
Core References
Third Party Advisory government-resource broken-link
https://www.usom.gov.tr/bildirim/tr-26-0155

Scores

CVSS v3 7.2
EPSS 0.0118
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
Profelis Information and Consulting Trade and Industry Limited Company/SambaBox 5.1 - 5.3
Published May 04, 2026
Tracked Since May 04, 2026