Command Injection Vulnerability in CoolerControl by CoolerControl
CVE-2026-5208

8.2HIGH

Key Information:

Vendor
CVE Published:
8 April 2026

What is CVE-2026-5208?

A command injection flaw exists in CoolerControl versions prior to 4.0.0, which permits authenticated attackers to execute arbitrary code with root privileges. This vulnerability is triggered through maliciously crafted alert names, where injected bash commands can be processed by the system. Consequently, this poses serious security risks enabling unauthorized control and exploitation of the affected system.

Affected Version(s)

coolercontrold 3.1.0 < 4.0.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://gitlab.com/lassi-3
.