Remote Code Execution Vulnerability in Asset Filters of Analysis REST Endpoint by Vendor
CVE-2026-64878

9.4CRITICAL

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64878?

A vulnerability exists in the asset filter parameters of the Analysis REST endpoint, where unvalidated input allows for the execution of shell metacharacters. This can lead to remote code execution under the permissions of a low-privileged operating system user, posing significant security risks. Exploiting this vulnerability could allow an attacker to execute arbitrary commands, potentially compromising the integrity and availability of the affected system.

Affected Version(s)

Security Center Linux 0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.