PT-2026-27108 · Mb Connect Line+1 · Mb Connect Line Mymbconnect24+3

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32968

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32968

Affected Products

Mb Connect Line Mymbconnect24
Myrex24V2
Myrex24V2.Virtual
Mbconnect24