HarborGuard / CVE
Back to search
CRITICALCVE-2026-5965Published Modified CNA twcert

CVE-2026-5965: NewSoft|NewSoftOA - OS Command Injection

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
10.1.8.3
Affected Products
1

Fix available

10.1.8.3
Affected packages
  • NewSoft / NewSoftOA
    < 10.1.8.3 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N