Description
The 
iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Published: 2026-04-16
Score: 9.3 Critical
EPSS: 2.3% Low
KEV: No
Impact: Command Injection
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update iSherlock-base-4.5 package to version 476 or later Update iSherlock-audit-4.5 package to version 261 or later Update iSherlock-base-5.5 package to version 476 or later Update iSherlock-audit-5.5 package to version 261 or later

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Thu, 16 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Hgiga
Hgiga isherlock-audit
Hgiga isherlock-base
Vendors & Products Hgiga
Hgiga isherlock-audit
Hgiga isherlock-base

Thu, 16 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
Description The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Title HGiga|iSherlock - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Hgiga Isherlock-audit Isherlock-base
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-04-24T07:23:51.324Z

Reserved: 2026-04-15T11:32:29.759Z

Link: CVE-2026-6349

cve-icon Vulnrichment

Updated: 2026-04-16T13:43:02.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-16T03:16:30.660

Modified: 2026-04-24T08:16:30.537

Link: CVE-2026-6349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T16:30:35Z

Weaknesses