OS Command Injection Vulnerability in CGServiSign by Changing
CVE-2026-15027

8.6HIGH

Key Information:

Vendor

Changing

Vendor
CVE Published:
23 September 2026

What is CVE-2026-15027?

CGServiSign, developed by Changing, is affected by an OS Command Injection vulnerability that allows unauthenticated remote attackers to exploit the local service interface. By enticing victims to visit a malicious web page, attackers can inject arbitrary operating system commands. This can lead to unauthorized command execution on the victim's computer, potentially compromising sensitive data and system integrity.

Affected Version(s)

CGServiSign Linux 1.0.23.1227

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.