PT-2026-27108 · Unknown · Com Mb24Sysapi Module

Christian Zäske

+1

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32968

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions com mb24sysapi module (affected versions not specified)
Description An unauthenticated remote attacker can exploit a remote code execution issue in the com mb24sysapi module, potentially leading to full system compromise. The root cause is the improper neutralisation of special elements used in an OS command. This is a variant of a previously known issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32968

Affected Products

Com Mb24Sysapi Module