Operating System Command Injection Vulnerability in UpSnap Web App
CVE-2026-49481

9.6CRITICAL

Key Information:

Vendor

Seriousm4x

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-49481?

The UpSnap web application, designed for wake on lan functionality, contains an OS command injection vulnerability in its device management feature. This issue arises from improper handling of user-controlled input within shell command templates. Specifically, malicious inputs can be injected into the wake_cmd and shutdown_cmd parameters, leading to arbitrary command execution on the server. This vulnerability impacts all versions before 5.4.0, allowing low-privileged users with permissions to create or edit devices to exploit the flaw. The issue has been addressed in version 5.4.0, which users are urged to upgrade to in order to mitigate potential security risks.

Affected Version(s)

UpSnap < 5.4.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.