PT-2026-41304 · Unknown · Oinone Pamirs

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2026-39052

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oinone Pamirs version 7.0.0
Description An issue exists via ScriptRunner where the run(String expression, String type, Map<String, Object> context) function evaluates attacker-controlled script expressions through the underlying script engine. This occurs because the process lacks sandboxing (a security mechanism for separating running programs) or allowlist restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-39052

Affected Products

Oinone Pamirs