CVE-2026-14448

Summary

An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in an OS command. This can result in a total loss of confidentiality, availability and integrity.

Affected Software

VendorProductVersion RangeStatus
MB connect linembCONNECT241.0.0 <= 2.20.0affected
MB connect linemymbCONNECT241.0.0 <= 2.20.0affected
MB connect linembCONNECT242.20.0affected
MB connect linemymbCONNECT242.20.0affected
HelmholzmyREX24V21.0.0 <= 2.20.0affected
HelmholzmyREX24V2.virtual1.0.0 <= 2.20.0affected
HelmholzmyREX24V22.20.0affected
HelmholzmyREX24V2.virtual2.20.0affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References