CVE-2026-3120: RCE in Profelis Informatics' SambaBox
Published May 4, 2026
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection.
This issue affects SambaBox: from 5.1 before 5.3.
Affected Software
1 affected component
Profelis Informatics SambaBox>=5.1<5.3
Event History
May 4, 2026
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-3120?
CVE-2026-3120 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2026-3120?
To fix CVE-2026-3120, upgrade SambaBox to version 5.3 or later.
3
What software is affected by CVE-2026-3120?
CVE-2026-3120 affects Profelis Informatics' SambaBox versions from 5.1 to below 5.3.
4
What type of vulnerability is CVE-2026-3120?
CVE-2026-3120 is a code injection vulnerability that allows OS command injection.
5
Is there a workaround for CVE-2026-3120?
There is no known workaround for CVE-2026-3120; the best solution is to upgrade the software.