An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.
https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-50772
https://docs.squirro.com/en/latest/products/cognitive-search.html