CVE-2026-66145: Code Injection
Published Aug 11, 2026
·Updated
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
Affected Software
1 affected component
GMS<=9.5.1 (Build 9510.1044)
Event History
Aug 11, 2026
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionWeakness
Data Sourced
via NVD·08:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66145?
CVE-2026-66145 has a risk rating of 89, indicating a high severity level.
2
What type of vulnerability is CVE-2026-66145?
CVE-2026-66145 is an unauthenticated remote code execution vulnerability.
3
How do I fix CVE-2026-66145?
To fix CVE-2026-66145, upgrade to GMS version 9.5.2 or later.
4
What impact does CVE-2026-66145 have on my system?
CVE-2026-66145 allows remote attackers to read sensitive data and perform arbitrary file writes.
5
Is CVE-2026-66145 exploitable without authentication?
Yes, CVE-2026-66145 can be exploited without authentication.