CVE-2026-40456

high

Description

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the "exec()" function without proper validation, allowing attackers to execute arbitrary operating system commands.

References

https://lms.org.pl/

https://github.com/chilek/lms/commit/9fcb4de19b7d76394898dbc124252b86b07ac0ed

https://cert.pl/posts/2026/06/CVE-2026-40455

Details

Source: Mitre, NVD

Published: 2026-06-18

Updated: 2026-06-22

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 8.6

Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N

Severity: High

EPSS

EPSS: 0.00947