CVE-2026-21719: OS Command Injection
Published Apr 17, 2026
·Updated
An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.
Affected Software
2 affected components
Cubecart CubeCart<6.6.0
Cubecart CubeCart<6.6.0
Event History
Apr 17, 2026
CVE Published
via MITRE·04:33 AM
Data Sourced
via MITRE·04:33 AM
DescriptionSeverity
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21719?
CVE-2026-21719 is considered a critical vulnerability due to its potential for arbitrary OS command execution.
2
How do I fix CVE-2026-21719?
To fix CVE-2026-21719, upgrade your CubeCart installation to version 6.6.0 or later.
3
What types of systems are affected by CVE-2026-21719?
CVE-2026-21719 affects all CubeCart versions prior to 6.6.0.
4
Who can exploit CVE-2026-21719?
An authenticated user with administrative privileges can exploit CVE-2026-21719 to execute arbitrary OS commands.
5
What actions should I take if I am using an affected version of CubeCart?
If you are using an affected version of CubeCart, you should immediately upgrade to version 6.6.0 or higher to mitigate the risk.