CVE-2026-6349: HGiga|iSherlock - OS Command Injection
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iSherlock-audit-4.5to a version that resolves this vulnerability.Fixed in 261 - Upgrade
Upgrade
iSherlock-audit-5.5to a version that resolves this vulnerability.Fixed in 261 - Upgrade
Upgrade
iSherlock-base-4.5to a version that resolves this vulnerability.Fixed in 476 - Upgrade
Upgrade
iSherlock-base-5.5to a version that resolves this vulnerability.Fixed in 476
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6349?
CVE-2026-6349 is classified as a critical severity vulnerability due to its potential for unauthorized command execution.
How do I fix CVE-2026-6349?
To address CVE-2026-6349, ensure that you update the iSherlock application to the latest version provided by HGiga that includes a patch for this vulnerability.
Who is affected by CVE-2026-6349?
All users of the HGiga iSherlock application are affected by CVE-2026-6349 if they have unpatched versions of the software.
Can CVE-2026-6349 be exploited remotely?
CVE-2026-6349 requires local access for exploitation, making it a local attack vector.
What are the potential consequences of CVE-2026-6349?
Exploitation of CVE-2026-6349 could lead to unauthorized execution of arbitrary OS commands, compromising server security and integrity.