HarborGuard / CVE
Back to search
CRITICALCVE-2026-6349Published Modified CNA twcert

CVE-2026-6349: HGiga|iSherlock - OS Command Injection

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
261
Affected Products
4

Fix available

261476
Affected packages
  • HGiga / iSherlock-base-4.5
    < 476 (from 0)
  • HGiga / iSherlock-audit-4.5
    < 261 (from 0)
  • HGiga / iSherlock-base-5.5
    < 476 (from 0)
  • HGiga / iSherlock-audit-5.5
    < 261 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N