Remote Code Execution Vulnerability in Aeon Load Time Series Segmentation Toolkit
CVE-2026-18287

7.8HIGH

Key Information:

Vendor

Aeon

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18287?

A security flaw in the Aeon load_time_series_segmentation_benchmark allows attackers to execute arbitrary Python code on compromised systems. This vulnerability emerges from improper validation of user-supplied strings, enabling remote code execution if a user interacts with a malicious web page or file. Successful exploitation can lead to serious security implications, as attackers may run arbitrary commands in the context of the running process.

Affected Version(s)

aeon 1.3.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.