Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 4.0.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:coolercontrol:coolercontrold:*:*:*:*:*:*:*:* |
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coolercontrol
Coolercontrol coolercontrold |
|
| Vendors & Products |
Coolercontrol
Coolercontrol coolercontrold |
Wed, 08 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names | |
| Title | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coolercontrold | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-04-08T12:55:51.455Z
Reserved: 2026-03-31T09:35:01.724Z
Link: CVE-2026-5208
Updated: 2026-04-08T12:55:47.478Z
Status : Analyzed
Published: 2026-04-08T12:16:22.383
Modified: 2026-04-16T01:06:47.997
Link: CVE-2026-5208
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:21:54Z