Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
No solution has been reported yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:civetweb_project:civetweb:1.16:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Civetweb Project
Civetweb Project civetweb |
|
| Vendors & Products |
Civetweb Project
Civetweb Project civetweb |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration. | |
| Title | Search path without quotes in CivetWeb | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-04-21T19:27:53.853Z
Reserved: 2026-04-08T12:34:46.460Z
Link: CVE-2026-5789
Updated: 2026-04-21T19:27:50.585Z
Status : Analyzed
Published: 2026-04-21T15:16:37.713
Modified: 2026-04-22T17:36:36.280
Link: CVE-2026-5789
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:46:24Z