Untriaged
Permalink
CVE-2026-5208
8.2 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coolercontrold
Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names
References
Affected products
coolercontrold
- <4.0.0
Package maintainers
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@codifryed Guy Boldon <gb@guyboldon.com>