Command Injection Vulnerability in PowSyBl Framework by PowSyBl
CVE-2026-55673

7.1HIGH

Key Information:

Vendor

Powsybl

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55673?

The PowSyBl framework, used for building power system-oriented software, is susceptible to command injection vulnerabilities prior to version 7.2.2. Both UnixLocalCommandExecutor and WindowsLocalCommandExecutor components improperly concatenate command arguments and environmental variables, enabling attackers to execute arbitrary shell commands. Received inputs that reach critical execution points within the APIs may lead to unintended command execution under the JVM user's privileges. Affected paths include 'action-simulator' and 'security-analysis'. The vulnerability is particularly severe in scenarios involving downstream CLI tools and multi-tenant grid-analysis services that might pass less-trusted data into the APIs.

Affected Version(s)

powsybl-core < 7.2.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.