CRITICALVulnerability
CVE-2026-9645
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
Properties
- severity
- CRITICAL
- score
- 9.9
- cve_id
- CVE-2026-9645
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- published_at
- 2026-05-28T21:16:34.950
- last_modified
- 2026-08-17T15:35:44.073
Related Entities (3)
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph