OS Command Injection Vulnerability in Cosminexus Component Container by Hitachi
CVE-2026-71376

9.8CRITICAL

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
8 September 2026

What is CVE-2026-71376?

An OS command injection vulnerability has been identified in the Cosminexus Component Container by Hitachi. This flaw could allow an attacker to execute arbitrary commands in the operating system context, potentially leading to unauthorized access or control over the affected systems. The vulnerability affects multiple versions of the software, making it critical for organizations utilizing Cosminexus to review the affected versions and implement necessary mitigations promptly.

Affected Version(s)

Cosminexus Component Container Windows 11-70-01 < 11-70-03

Cosminexus Component Container Windows 11-60 < 11-60-03

Cosminexus Component Container Windows 11-50 <= 11-50-03

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.