CVE-2026-6349

CRITICAL

HGiga|iSherlock - OS Command Injection

Title source: cna

Description

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Scores

CVSS v4 10.0
EPSS 0.0134
EPSS Percentile 80.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Details

CWE
CWE-78
Status published
Products (4)
HGiga/iSherlock-audit-4.5 < 261
HGiga/iSherlock-audit-5.5 < 261
HGiga/iSherlock-base-4.5 < 476
HGiga/iSherlock-base-5.5 < 476
Published Apr 16, 2026
Tracked Since Apr 16, 2026