PT-2026-21659 · Unknown · Hummerrisk
Ana10Gy
·
Published
2026-02-24
·
Updated
2026-02-24
·
CVE-2026-3066
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HummerRisk versions up to 1.5.0
Description
A flaw exists in HummerRisk that allows for command injection. The issue is located within the
fixedCommand function in the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformUtils.java, part of the Cloud Compliance Scanning component. This allows for remote execution of manipulated commands. The exploit for this issue has been published.Recommendations
Versions prior to 1.5.0 should be used. As a temporary workaround, consider restricting access to the
fixedCommand function until a patch is available.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hummerrisk