Skip to content
CVE-2026-22313: OS Command Injection Vulnerability Discovered

CVE-2026-22313: OS Command Injection Vulnerability Discovered

First seen 17 Jun 2026, 10:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 10:08 UTC
  • CVE-2026-22313 allows OS command injection by authenticated users.
  • A patch is available; immediate application is recommended.
  • No evidence of exploitation has been confirmed as of now.

CVE-2026-22313 is an OS command injection vulnerability affecting devices with a webserver that exposes a REST API authenticated via token. Authenticated attackers with access to the management network can execute arbitrary OS commands with administrative permissions. Currently, there is no evidence of public proof-of-concept or confirmed exploitation. A patch has been released, and organizations are advised to apply it immediately. Security measures such as restricting network access and implementing strong authentication for API tokens are recommended. The vulnerability was first detailed on June 16, 2026, by NVD and GitHub Advisories. The CVSS score for this vulnerability indicates a high severity level.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-16
CVE-2026-22313 published
NVD published details of CVE-2026-22313, an OS command injection vulnerability affecting devices with a REST API.
Feedly
2026-06-17
Vulnerability reported by The Hacker Wire
The Hacker Wire reported on CVE-2026-22313, detailing the attack vector and potential impact.
www.thehackerwire.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-22313 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed