OS Command Injection Vulnerability in SambaBox by Felisify Information Technologies
CVE-2026-85523
8.8HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 6 October 2026
What is CVE-2026-85523?
A vulnerability in SambaBox allows for OS command injection, enabling attackers to execute arbitrary commands on the host operating system. This issue arises from improper handling of input, allowing special elements to be included without appropriate validation or neutralization. Users of SambaBox versions prior to 5.4.1 are particularly at risk and should consider immediate updates to mitigate this threat. Ongoing monitoring and risk assessment are recommended to avoid exploitation.
Affected Version(s)
SambaBox 0 < 5.4.1
