Skip to content
Critical Code Injection Vulnerability in Floci Affects Unauthenticated Users

Critical Code Injection Vulnerability in Floci Affects Unauthenticated Users

First seen 11 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 18:31 UTC
  • •CVE-2026-108598 affects Floci versions 1.1.0 to 2.2.0.
  • •The vulnerability allows unauthenticated command execution via REST API.
  • •No public exploits are available yet, but the CVSS score is critical at 9.8.

A critical code injection vulnerability, CVE-2026-108598, has been identified in Floci versions 1.1.0 to 2.2.0, allowing unauthenticated attackers to execute arbitrary OS commands via the VtlTemplateEngine. Attackers can exploit this flaw by creating a REST API with a MOCK integration that leverages $util reflection to access Runtime or ProcessBuilder. The vulnerability has a CVSS score of 9.8, indicating its critical nature. Currently, there are no public proof-of-concept exploits available, and remediation efforts are under review. The vulnerability was published on October 10, 2026, but is not listed in the CISA KEV database. The situation remains urgent as organizations are advised to monitor for updates and potential patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-10
CVE-2026-108598 published
Floci disclosed a critical code injection vulnerability allowing unauthenticated command execution.
Feedly

More articles in this cluster (2)

Following this threat?

Track CVE-2026-108598 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Floci are affected?
Floci versions 1.1.0 through 2.2.0 are affected by this vulnerability.
Is there a patch available?
Currently, there are no specific patches mentioned, and remediation efforts are under review.
What is the severity of this vulnerability?
The vulnerability has a CVSS score of 9.8, categorizing it as critical.