CRITICALVulnerability

CVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

Properties

severity
CRITICAL
score
9.4
cve_id
CVE-2026-66147
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
published_at
2026-08-11T21:17:49.173
last_modified
2026-08-28T18:58:27.140

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66147 — Ninja Signal Threat Intelligence | Ninja Signal