PT-2026-22930 · 2N · 2N Access Commander

Published

2026-03-04

·

Updated

2026-03-05

·

CVE-2025-59783

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions 2N Access Commander version 3.4.1
Description The user synchronization API endpoint in 2N Access Commander version 3.4.1 lacks sufficient input validation, which allows for OS command injection. Exploitation requires administrator privileges.
Recommendations Apply input validation to the user synchronization API endpoint.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59783

Affected Products

2N Access Commander