OS Command Injection in Vertex-App Log Viewer Endpoint by Vertex
CVE-2026-11408
Key Information:
- Vendor
Vertex-app
- Status
- Vendor
- CVE Published:
- 6 June 2026
Badges
What is CVE-2026-11408?
A vulnerability exists within the Log Viewer Endpoint of the vertex-app that allows for OS command injection due to improper handling of query parameters in the LogMod.js file. This weakness enables remote attackers to execute arbitrary commands on the server, potentially leading to significant security breaches. The issue affects versions of the vertex-app prior to 2026.02.12. A patch has been released (commit 805d82e7100d49b79b3beb1b9420e8e458987198) to rectify this fault, and it is essential for users to apply this update promptly to safeguard their systems.
Affected Version(s)
vertex 2026.02.0
vertex 2026.02.1
vertex 2026.02.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
