SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90444

HIGH · CVSS 8.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability exists in a file-transfer interface that improperly handles attacker-controlled filenames, allowing authenticated users to inject shell metacharacters. This can lead to arbitrary command execution with the process's privileges, enabling attackers to manipulate log data and potentially gain further access within the internal network. Organizations using this file-transfer interface should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-90444
Severity
HIGH
CVSS
8.7
EPSS
0.23%

Original NVD Description

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.