OS Command Injection Vulnerability in webgjc web_robot by webgjc
CVE-2026-90492

5.3MEDIUM

Key Information:

Vendor

Webgjc

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90492?

A security flaw exists in the webgjc web_robot versions 2.4.0, 2.5.0, and 2.8.0, where the function controller_listen/controller_recover in the file py/web.py is susceptible to OS command injection. By manipulating the 'case_name' argument, an attacker can execute arbitrary commands on the server remotely. This vulnerability has been publicly disclosed, indicating that it may be actively exploited by attackers. The vendor was informed prior to the public disclosure but has not provided a response.

Affected Version(s)

web_robot 2.4.0

web_robot 2.5.0

web_robot 2.8.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Telqrrr (VulDB User)
VulDB CNA Team
.