CVE-2025-26818: Command Injection
Published Apr 3, 2025
·Updated
Netwrix Password Secure through 9.2 allows command injection.
Affected Software
2 affected components
Netwrix Password Secure<=9.2
Netwrix Password Secure<9.2.2
Event History
Apr 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26818?
CVE-2025-26818 has a critical severity due to the command injection vulnerability it introduces.
2
How do I fix CVE-2025-26818?
To fix CVE-2025-26818, upgrade Netwrix Password Secure to a version later than 9.2 that addresses this vulnerability.
3
What types of attacks can CVE-2025-26818 enable?
CVE-2025-26818 can allow attackers to execute arbitrary commands on the affected system.
4
Which versions of Netwrix Password Secure are affected by CVE-2025-26818?
CVE-2025-26818 affects all versions of Netwrix Password Secure up to and including 9.2.
5
Is there a workaround for CVE-2025-26818 until a patch is available?
Currently, there are no documented workarounds for CVE-2025-26818; upgrading to a patched version is recommended.