PT-2026-2293 · Tinyweb · Tinyweb

Maxim Masutin

·

Published

2026-01-12

·

Updated

2026-01-12

·

CVE-2026-22781

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions TinyWeb versions prior to 1.98
Description TinyWeb is a web server for Win32. Versions of TinyWeb HTTP Server before 1.98 contain a flaw that allows for operating system command injection. This occurs through CGI ISINDEX-style query parameters, which are passed as command-line arguments to a CGI executable using the Windows CreateProcess() function. A remote attacker who does not need to be authenticated can execute arbitrary commands on the server by injecting Windows shell metacharacters into HTTP requests. The vulnerable parameters are passed to the CreateProcess() function.
Recommendations Update to TinyWeb version 1.98 or later.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22781
GHSA-M779-84H5-72Q2

Affected Products

Tinyweb