CVE-2026-34107

CRITICAL

Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php

Title source: cna
STIX 2.1

Description

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to execute arbitrary OS commands on the server.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0068
EPSS Percentile 48.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
guardian/language-system < e42c395ec4b03fe62973a669c9209a673838b8a4
Published Jul 01, 2026
Tracked Since Jul 01, 2026