CVE-2026-27550: Command Injection in Field_Shadow_Password Class
Published Sep 16, 2026
·Updated
A low-privileged remote attacker can exploit a command injection vulnerability in the FieldShadowPassword class using operator credentials allowing execution of commands with root privileges on the device.
Event History
Sep 16, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs low-privileged remote access using operator credentials. No user interaction is required.
2
What is the impact after successful exploitation?
Successful exploitation allows execution of commands with root privileges on the affected device, with high impact to confidentiality, integrity, and availability.