PT-2026-4733 · Unknown · Wellchoose Single Sign-On Portal System

Yucheng Lin

·

Published

2026-01-26

·

Updated

2026-03-11

·

CVE-2026-1428

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WellChoose Single Sign-On Portal System (affected versions not specified)
Description The WellChoose Single Sign-On Portal System contains an OS Command Injection issue. Authenticated remote attackers can inject arbitrary OS commands and execute them on the server. The issue allows for the injection of commands, potentially granting attackers unauthorized access and control over the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1428

Affected Products

Wellchoose Single Sign-On Portal System