CVE-2026-66147: Code Injection
Published Aug 11, 2026
·Updated
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
Affected Software
1 affected component
GMS GMS Dispatcher Service<=9.5.1
Event History
Aug 11, 2026
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66147?
CVE-2026-66147 has a risk rating of 95, indicating a critical severity level.
2
How do I fix CVE-2026-66147?
To mitigate CVE-2026-66147, update the GMS Dispatcher Service to version 9.5.2 or later.
3
What type of vulnerability is CVE-2026-66147?
CVE-2026-66147 is classified as an unauthenticated command injection vulnerability.
4
Can CVE-2026-66147 be exploited remotely?
Yes, CVE-2026-66147 can be exploited by remote attackers through specially crafted requests.
5
What could be the impact of CVE-2026-66147?
Exploitation of CVE-2026-66147 could lead to remote code execution on affected systems.