iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update iSherlock-base-4.5 package to version 476 or later Update iSherlock-audit-4.5 package to version 261 or later Update iSherlock-base-5.5 package to version 476 or later Update iSherlock-audit-5.5 package to version 261 or later
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV3_1
|
Thu, 16 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hgiga
Hgiga isherlock-audit Hgiga isherlock-base |
|
| Vendors & Products |
Hgiga
Hgiga isherlock-audit Hgiga isherlock-base |
Thu, 16 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server. | |
| Title | HGiga|iSherlock - OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-04-24T07:23:51.324Z
Reserved: 2026-04-15T11:32:29.759Z
Link: CVE-2026-6349
Updated: 2026-04-16T13:43:02.940Z
Status : Awaiting Analysis
Published: 2026-04-16T03:16:30.660
Modified: 2026-04-24T08:16:30.537
Link: CVE-2026-6349
No data.
OpenCVE Enrichment
Updated: 2026-04-28T16:30:35Z