PT-2026-21659 · Unknown · Hummerrisk

Ana10Gy

·

Published

2026-02-24

·

Updated

2026-02-24

·

CVE-2026-3066

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HummerRisk versions up to 1.5.0
Description A flaw exists in HummerRisk that allows for command injection. The issue is located within the fixedCommand function in the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformUtils.java, part of the Cloud Compliance Scanning component. This allows for remote execution of manipulated commands. The exploit for this issue has been published.
Recommendations Versions prior to 1.5.0 should be used. As a temporary workaround, consider restricting access to the fixedCommand function until a patch is available.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-3066

Affected Products

Hummerrisk