OS Command Injection in iSherlock by HGiga
CVE-2026-6349

10CRITICAL

Key Information:

Vendor

Hgiga

Vendor
CVE Published:
16 April 2026

What is CVE-2026-6349?

iSherlock, developed by HGiga, has a vulnerability that allows unauthenticated local attackers to execute arbitrary operating system commands on the server. This flaw arises from insufficient input validation, enabling attackers to manipulate system commands through specially crafted requests. Such vulnerabilities can lead to significant security breaches, including unauthorized data access and control over the affected system.

Affected Version(s)

iSherlock-audit-4.5 0 < 261

iSherlock-audit-5.5 0 < 261

iSherlock-base-4.5 0 < 476

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.